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Preface 



This volume contains the workshop proceedings of DEON 2004, the Seventh 
International Workshop on Deontic Logic in Computer Science. The DEON 
workshop series aims at bringing together researchers interested in topics re- 
lated to the use of deontic logic in computer science. It traditionally promotes 
research in the relationship between normative concepts and computer science, 
artificial intelligence, organisation theory, and law. In addition to these topics, 
DEON 2004 placed special emphasis on the relationship between deontic logic 
and multi-agent systems. 

The workshop was held in Madeira, Portugal, on 26-28 May 2004. This vol- 
ume includes all 15 papers presented at the workshop, as well as two abstracts 
from the two outstanding invited speakers we were privileged to host: Prof Mark 
Brown (Syracuse University, USA), and Prof Mike Wooldridge (University of 
Liverpool, UK). The reader will find that the topics covered span from the- 
oretical investigations on deontic concepts and their formalisation in logic, to 
the use of deontic formalisms to verify and reason about multi-agent systems 
applications. We believe this makes it a well-balanced and interesting volume. 

We wish to thank all those who contributed to this workshop, and especially 
the authors of the submitted papers and the referees. They were all forced to 
work on a very tight timescale to make this volume a reality. 



April 2004 



Alessio Lomuscio 
Donald Nute 
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Obligation, Contracts, and Negotiation 



Mark A. Brown 



Philosophy Department 
Syracuse University 
Syracuse, NY 13210, USA 

mabrownOsyr . edu 



Many obligations can be seen as arising from contractual arrangements (or from 
situations resembling contractual arrangements) among agents. My obligation 
to repay you the $100 I borrowed is associated with a simple (quite possibly 
tacit and informal) contractual arrangement between us. My obligations as an 
employee of my university are associated with contractual arrangements with 
my university, which may be considered a collective agent. My university in turn 
has certain obligations to me. But some obligations change over time as a result 
of changing circumstances, and in at least some cases the changes that occur 
can be thought of as involving a renegotiation of a contract among the parties 
involved. When I pay back half the money I owe you, I have not fulfilled my orig- 
inal obligation; but neither does that original obligation to pay you $100 still 
stand. Instead, we may consider, we have renegotiated my contract with you 
so that my remaining obligation is to pay you $50 (or, depending on details of 
the negotiation, perhaps $50 plus interest or a late fee). Analogous, though usu- 
ally more explicit, renegotiations of contracts are commonplace in the corporate 
world as well. 

As we examine this way of looking at normative situations, we find a number 
of complications which must be considered, many of which we are accustomed 
to set aside in simpler treatments of deontic logic. We must consider the rela- 
tionships among distinct agents, not just consider the normative positions of one 
agent at a time. We need to make room for corporate agents, i.e. agents which 
are organizations or groups of other agents. We need to consider that a sin- 
gle agent may be involved in multiple contractual arrangements, and thus may 
have a number of different normative roles simultaneously. As a result, we must 
make room for conflicting obligations. And we must allow for various kinds of 
modifications of contractual arrangements over time, including negotiation and 
renegotiation. Moreover, ultimately we must consider ways in which complex 
organizations are related to their changing roster of participant agents, whose 
roles within the organization alter over time. 

In this paper, I will discuss a number of the issues which arise in any attempt 
to formalize a contractual model of our changing normative situations. 
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Social Laws in Alternating Time 



Michael Wooldridge 
University of Liverpool 



Since it was first proposed by Moses, Shoham, and Tennenholtz, the social laws 
paradigm has proved to be one of the most compelling approaches to the offline 
coordination of multiagent systems. In this paper, we make three key contribu- 
tions to the theory and practice of social laws in multiagent systems. First, we 
show that the Alternating-time Temporal Logic of Alur, Henzinger, and Kupfer- 
man provides an elegant and powerful framework within which to express and 
understand social laws for multiagent systems. Second, we show that the ef- 
fectiveness, feasibility, and synthesis problems for social laws may naturally be 
framed as ATL model checking problems, and that as a consequence, existing ATL 
model checkers may be applied to these problems. We illustrate the concepts and 
techniques developed by means of a running example. 

(joint with Wiebe van der Hoek and Mark Roberts) 
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Combinations of Tense and Deontic Modality 



Lennart Aqvist 

Department of Law, Uppsala University 
P.O.Box 512, S-751 20 Uppsala, Sweden 
lennart . aqvist@jur . uu . se 



Abstract. We consider three infinite hierarchies of what I call “two-dimen- 
sional temporal logics with explicit realization operators”, viz. (i) one without 
historical or deontic modalities, (ii) one with historical but without deontic mo- 
dalities, and (iii) one with historical and with dyadic deontic modalities for 
conditional obligation and permission. Sound and complete axiomatizations are 
obtained for all three hierarchies relative to a simplified version of the finite co- 
ordinate-system semantics given for so-called T x W logic of historical neces- 
sity in Aqvist (1999). 

Keywords: temporal realization operators, historical necessity, conditional ob- 
ligation, finite two-dimensional co-ordinate system, frame constants. 



1 Introduction 

The purpose of this paper is to investigate some crucial properties of an infinite hier- 
archy of logics combining (i) a logic for the temporal realization operator R t [“it is 
realized (true) at time t that”; see Rescher (1966), Rescher and Urquhart (1971)] with 
(ii) a modal logic for a temporally dependent necessity-modality, viz. “historical ne- 
cessity” or “inevitability” [Aqvist (1999)], and with (iii) a dyadic deontic logic for 
conditional obligation [Aqvist (1997, 2000)]. 

In order to provide some necessary background to our present enterprise, let us 
briefly consider the recent contribution Carmo and Jones (2002): Section 7.1, where 
the authors make a number of useful observations concerning so-called temporal 
approaches to the semantics of deontic notions (like those of obligation and permis- 
sion). The most important of these observations are, in my opinion, the following: 

(I) The temporal approaches at issue are generally based on tree-structures repre- 
senting branching time with the same past and open to the future. 

(II) On top of these tree-structures, temporal deontic logics typically define one mo- 
dal necessity operator, expressing some kind of inevitability or historical necessity, 
plus deontic obligation operators of either a monadic or dyadic kind (where the latter 
are to reflect notions of conditional obligation). 

(III) A main difference appears in the way the temporal dimension is syntactically 
reflected in the formal language of the logics considered. One family of those logics 
indexes the modal and deontic operators with temporal terms, whereas another family 
introduces temporal operators that can be iterated and combined with the modal and 
deontic operators. 
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(IV) Leaving the “temporal-operator” family aside for the time being, we emphasize 
that a characteristic feature of the “indexed” temporal deontic logics is the presence 
in them of time-indexed modal and deontic operators. Carmo and Jones (2002) point 
out that the time-index could be “separated” from the modal / deontic operators so as 
to yield a uniform semantical and logical setting for analyzing the modal / deontic 
component of both types of temporal deontic logics, mentioned in (III) above. This, 
they say, can be achieved by means of the temporal realization operator R t [“it is 
realized (true) at time t that”] of Reseller and Urquhart (1971). Let us add here that 
this means that, instead of writing, like van Eck (1981), Loewer and Belzer (1983), 
and many others, 

/V ( ,4 for “it is necessary at time t that A”, 

OjA for “it is obligatory at time t that A”, and 
p t for “p-at-tiine-f” 

we are to write, following Bailhache (1991, 1993) and myself in Aqvist (2002), 

RJVA, 

R t OA, and 
R t p 

in order to express the corresponding notions, where the “separation” just spoken of is 
made perfectly clear and explicit. 

In view of the above observations, the following problem naturally presents itself: 
What is the logic of the operators R r N, and O, considered (i) separately 1 , and (ii) in 
combination with one another? As for the logic of the modal operator N of historical 
necessity (considered separately), the reader is referred to my earlier study Aqvist 
(1999) and, as for the logic of the dyadic deontic operator O (again considered sepa- 
rately), to my previous studies Aqvist (1997) and Aqvist (2000). As far as the infor- 
mal, philosophical motivation for our concentrating on precisely the logics developed 
in those studies is concerned, we refer the reader to the introductions to those papers, 
where most relevant additional information can be found. However, some main points 
made in earlier work of mine deserve to be rehearsed here; this will be done at the end 
of the present introduction. 

Two main novelties of the present paper are as follows. 

(A) Inasmuch as we deal with the problem of combining the logic of R t with that of 
N, we must be aware that the latter is represented as a special form of general two- 
dimensional modal logics in the sense of Segerberg (1973). Two-dimensionality 
means in the approach of Aqvist (1999) that, in the semantics for N , we work with 
frames considered as (finite) two-dimensional co-ordinate systems, where it is possi- 
ble to distinguish between the longitude (i.e. x- value) and the latitude (i.e. y-value) of 
any point in such a co-ordinate system. Again, on that approach to the semantics 2 



1 One should observe here that considering those logics “separately” does not preclude our 
basic two-dimensional temporal logic from containing other modal operators of great interest 
in their own right. See e.g. Section 2 below in fine, category (vi). 

2 We may notice here that our present semantics for N is simplified as compared to the one 
proposed in Aqvist (1999), where I worked simultaneously with two different semantical 
frameworks, a “relational” one and a “non-relational" one. As was correctly pointed out by 
the yPL-referee of that paper, this complication is unnecessary and can be overcome. How- 
ever, the simplification achieved here is different from the one suggested by him / her. 
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for N, times were interpreted as longitudes, and worlds , or histories , as latitudes in 
such systems. 

Now, facing the problem of combining the logic of N with a connective expressing 
temporal realization, we immediately see that the Rescher operator R t , read as “it is 
realized at time t that”, is not the one that comes most naturally to mind, because it is 
neither discriminative nor general enough. A more plausible and natural candidate for 
being combined with our N of historical necessity (inevitability) would instead seem 
to be R rh , read as “it is realized at time t in history h that”. However, as will be seen 
in Sections 3-4 below, Reseller’s R t is readily definable 3 in terms of R th , using the 
technique of so-called systematic frame constants, which was a characteristic feature 
of the Aqvist (1999) approach to the logic of historical necessity. 

Upshot: the above combination problem will in this paper be re-formulated as one 
of combining the logic of the more general operator R th with that of N and that of O. 

(B) Let us next consider the question how to combine our logic of N with the one for 
the dyadic deontic operator O, proposed in Aqvist (1997, 2000), where we encounter 
a new application of the technique of systematic frame constants: they are, in the 
present deontic context, taken to represent different “levels of perfection” (as ex- 
plained in those papers). It turns out that this problem admits of a fairly simple solu- 
tion: (i) co-ordinate the various levels of perfection (denoted by our new frame con- 
stants) with the latitudes (representing worlds, or histories) in the semantics for N, and 
then (ii) re-interpret the modal operators for universal necessity and universal possi- 
bility used in Aqvist (1997, 2000) precisely as historical necessity and historical 
possibility in the sense of our present logic of N and M. 

Having premised these observations, we can now outline the plan of this paper as 
follows. 

In Sections 2-4 we present the syntax, semantics and proof theory for an infinite 
hierarchy Rxy (with x, y any natural numbers in co) of two-dimensional temporal lo- 
gics with explicit realization operators If and R th without historical or deontic modali- 
ties. Section 5 establishes two fundamental results on so-called canonical Re- 
structures (the proofs of which are given in the Appendix of an as yet unpublished 
paper, Aqvist (2004)); together they yield strong as well as weak completeness of the 
logics (axiomatic systems) Rxy by means of the more or less standard argument given 
at the end of Section 5. Again, Sections 6-8 are devoted to the study of a new hierar- 
chy HRxy (x, ye co) of logics with the historical modalities N and M added to the 
vocabulary of the Rxy, but still without deontic modalities: the semantics and proof 
theory of the systems Rxy are extended to the HRyy, for which we obtain extended 
completeness results (main proofs being again relegated to the Appendix of Aqvist 
(2004)). Finally, in Sections 9 - 11, we achieve a desired extension of our R/R lh lo- 
gics HRyy of historical necessity to a third infinite hierarchy DHRxym (x, y, m e co) 
of dyadic deontic logics of conditional obligation and permission, for which similiar 
results are obtained in the same spirit. 



3 See e.g. axiom schema A3(a) in Section 4 infra. Again, from axiom schemata A4(d)-(f) in 

the same section it appears that even the three operators N lg , N lar and □ (as well as their 

duals), introduced as primitives in Section 2 infra, are definable in terms of R th and the 

frame constants a. and b,. This is easily verified by the reader. 

1 J 
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We close this introduction by rehearsing some main points in earlier work of mine, 
the most important of which are as follows. 

(i) In Aqvist (1999) we gave two types of semantics for our proposed infinite hierar- 
chy of logics of historical necessity and illustrated how they differ in their treatment 
of that notion by means of two contrasting diagrams. According to the first type, we 
interpret sentences of the forms NA and MA (my present notation) relative to tree- 
structures like 





' histories 
(worlds) 


~ • 


times 



by telling under what conditions such a sentence is true at a time in a history. On this 
approach, truth is thus relative to two indices. According to the second type of seman- 
tics, we proceed as follows: transform (convert) any tree-structure like the one shown 
above into a rectangular grid 




histories 

(worlds) 



where the encircled colonies of points represent equivalence classes under a certain 
equivalence relation on the ‘longitudes’ (heuristically times). The truth conditions for 
sentences of the forms NA and MA (my present notation) are then given in terms of 
this equivalence relation in the standard manner, i.e. truth is relative to just one index 
on this approach, viz. any point in the rectangular space. 

We note that the two types of structure relative to which we interpret sentences of 
the forms NA and MA are to a certain extent analogous to the so-called T x W frames 
and separated 

T x W frames in von Kutschera (1997). It turned out that our respective complete- 
ness proofs were facilitated by his use of separated T xW frames and my use of rec- 
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tangular grids instead of the rival structures just mentioned, i.e. T x W frames and 
unconverted / unseparated trees. 

(ii) An important difference between the Aqvist (1999) approach and the one advo- 
cated by von Kutschera (1997) is due to the fact that, on the former, we assumed time 
to be discrete and finite in the sense of having a beginning and an end. The main mo- 
tivation for thus limiting our framework to a discrete and finite one goes back to my 
work on Causation in the Law together with Philip Mullock in our joint book Aqvist 
and Mullock (1989), which was judiciously reviewed by von Kutschera in the review 
von Kutschera (1996), dealing primarily with the philosophically relevant aspects of 
our enterprise. In Aqvist and Mullock (1989) we developed a detailed theory of 
causation by agents and the representation of causal issues in Tort and Criminal Law, 
which is based on a version of Games and Game Theory in Extensive Form and 
where legal cases (Anglo-American, Swedish, German) are examined and graphically 
represented by means of game trees. When embarking on our project we felt that 
using a discrete and finite framework was the natural starting point, mainly because of 
what we took to be the fundamentally fmitistic nature of legal reasoning. In his 
(1996) review von Kutschera points out that this, of course, amounts to a partly seri- 
ous limitation of our model. 

However, he agrees with us on the need for a theory of liability and causation in 
the law that is, in the first place, intuitively clear in the sense of being sufficiently 
simple to apply. On the other hand he emphasizes that, since no simple model fits all 
the complex cases of human life, one has to find a compromise between simplicity 
and scope of applicability, whence he suggests that further refinements of our model 
be made later on according as needs for such refinements arise. 

(iii) An interesting point intimately bound up with the foregoing one is this. The dis- 
crete and finite framework used in Aqvist and Mullock (1989), and later in Aqvist 
(2002a), turns out to be fruitful in enabling us to explicate and represent formally the 
useful distinction between (i) basic action-sentences asserting that such and such an 
act is performed / omitted by an agent, and (ii) causative action-sentences asserting 
that by performing / omitting a certain act, an agent causes that such and such a state- 
of-affairs is realized (e.g. comes about / ceases / remains / remains absent, - see von 
Wright (1983), p. 173 f.).As appears from Aqvist (2002a), the discreteness property 
of our framework is then seen to play an important role in the present context. 

(iv) Again, the temporal setting of Aqvist and Hoepelman (1981) happened to be 
infinite - in the sense of requiring a denumerably infinite number of times and admit- 
ting a denumerably infinite number of histories, which were all taken to be of infinite 
length. However, its treatment of the Chisholm Contrary-to-Duty Paradox - a key 
problem in deontic logic - would, I suggest, be best understood in a finite framework 
like the one proposed here and in Aqvist (1999). Note also that Aqvist and Hoepel- 
man (1981) represents an early attempt to combine temporal-logic-with-historical- 
necessity precisely with dyadic deontic logic of the sort studied in Aqvist (1997, 
2000 ). 

(v) The problem of combining the discrete and finite approach adopted in Aqvist 
(1999) and the present paper with the discrete and infinite one used in Aqvist and 
Hoepelman (1981) remains open. 
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2 Syntax of the Systems Rxy of Two-Dimensional Temporal Logic 
with Explicit Realization Operators R t [“It Is Realized at Time t 
That”] and R th [“It Is Realized at Time t in History h That”] 

The vocabulary (morphology, alphabet, language) of the systems Rxy ( x , y e CO) is a 
structure made up of the following disjoint basic syntactic categories: 

(i) An at most denumerable set Prop of propositional variables. 

(ii) Propositional constants, subdivided into 

(a) traditional: T(verum) and Mfalsum), and 

(b) ‘new’: two families of systematic frame constants, viz. 

{ a j} jea) , indicating positions on the x-axis [‘longitudes’]; 

! hj }j e or indicating positions on the y-axis [‘latitudes’]. 

(iii) A set NT = { t i } ie 0) of names of times ( temporal names) as well as a set NH = 
{hj}j ea of names of histories (‘ worlds ' ). 

(iv) The Boolean sentential connectives — i, a, v, — with their usual readings. 

(v) An indexed family ! Pt i } j£ o; of one -place temporal realization operators, where 
Rt; is read as “it is realized at time t i that”, as well as a doubly indexed family 
{ Rtfij }, j e m of one-place time-history realization operators, with Rtf- read as 
“it is realized at time in history (world) hj that”. 

(vi) Three pairs ( N ,at , M lal ), (N lg , M ,g ) and (□,■ 0 ’) of one-place modal operators in 
two-dimensional temporal logic, the readings of which will be considered 
in a moment. 

For any natural numbers x, y, we then define recursively the set Sent of well 
formed sentences of Rxv in the straightforward manner, i.e. in such a way that all 
propositional variables and constants will be (atomic) sentences; moreover. Sent will 
be closed under every connective in the categories (iv) - (vi) supra. In particular, as 
far as the category (v) is concerned, we stipulate that if f ( e NT and A e Sent, then 
Rtfi e Sent; and that if in addition hj e NH, then Rthf\ e Sent (this being the only 
non-standard clause in our recursive definition of Sent). 

As to the readings of the one-place modalities in the category (vi), we tentatively 
invoke the following spatial metaphors: 

N la, A - everywhere on this latitude, A 
M la 'A - somewhere on this latitude, A 
N^A - everywhere on this longitude, A 
M'sA - somewhere on this longitude, A 
OA - everywhere, A 
<>A - somewhere, A. 



3 Semantics for Rry: Frames, Models and Truth Conditions 

Rxy-Frames. For any pair of natural numbers (x, y), we mean by a R xy-frame an 
ordered quadruple 
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F= ( U,(u 0 , e 0 , n Q ), ({^ l } ie0) ,x),([w ] ) ]em ,y)) 

where: 

(i) U 1=0 [U is a non-empty, finite set of points in time]. 

(ii) w 0 , e 0 , n () are designated members of U [heuristically, u 0 is the origin in U, e 0 is 
the eastern limit of U , and n Q is the northern limit of U], 

(iii) {^j} iea) is an infinite sequence of subsets of U [heuristically times ] and x is the 
first natural number under consideration. 

Let 7 = [t 0 , T|,...,T v }. We then require the set T to be a partition of U in the fa- 
miliar sense that 
(iii:a) T 0 U ... UT t = U. 

(iii:b) For all i,j e co with 0 < i =tj < x: x ; nx ; = 0. 

(iii:c) For each i e 0 ) with 0 < i < x: T ( =1 0. 

(iii:d) For each i e 0 ) with x < i: T ( = 0. 

(iv) {wj} j 6 m is an infinite sequence of subsets of U [heuristically histories, 
worlds ] and y is the second natural number under consideration. 

Let W = {w 0 , w j,..., w y }. We require the set W to be a partition of U in the sense 
that 

(iv:a) w 0 u ... u w = U. 

(iv:b) For all i, j g co with 0 < il=j < y: w t n vv ; = 0. 

(iv:c) For each j & CO with 0 < j < y: Wjl=0. 

(iv:d) For each j e CO with y < j: w- = 0. 

Furthermore, we require any Rxy- frame to satisfy the following additional condi- 
tions: 

(v) For each t in T and each w in W there is exactly one u in U such that {u} = T 
n w. 

(vi) { m 0 } = x 0 n w 0 , { e 0 } = x x n w 0 , and { « 0 } = x 0 n w y . 

Rxy-Models and Truth Conditions. Let F = (U, (« 0 , e 0 , n 0 ), ({x ; } ;e of x), ( { w- } ■ 6 of 
y)) be any Rrv-frame. By a valuation on such a frame we mean any function V which 
to each propositional variable p in Prop assigns a subset V(p) of Tx W, i.e. a certain 
set of ordered pairs (t, w) with T e T and w e W. 

By a R xy-model we then mean an ordered triple M = (F, V, v) the first term of 
which is a Rxy-frame, the second a valuation on that frame, and where v is the func- 
tion defined on NT u NH such that, for all i e or. 



v(*,-) = ( 



and such that, for all / e or. 



T-, if 0 < i < x 
0, otherwise, i.e. if x < i 



Wj, if 0 <j<y 

v(hj) = { 



0, otherwise, i.e if v < j 
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Let M = ((U, (m 0 , e 0 , n 0 ), ({x,.},. effl , x), ({w ; } ;e(U , >')), V, v) be a Rxy-model. We can 
now tell what it means for any sentence A to be true at a time x e T = (x 0 , x p ...,x } 
in a world w e W = {w 0 , w 1 ,...,w v } in M (in symbols: M , x, w |= A) by the following 
recursion: 

M, x, w |= p iff (x, w) g V(jr), for any p in Prop 
M, x ,w |= T 
not: M, X,w \— J_ 

T = Xj, if 0 <i<x 

M, t, w |= a t (ie co) iff { 

T ^ T, otherwise, i.e. if x < i 



M,x,w |= bj (je co) iff 



w = Wj, if 0<j<y 
wAw, otherwise, i.e. if y < j 



If A is a Boolean compound, the recursive definition goes on as usual. We then 
handle sentences having the characteristic one-place Rxy-connectives as their main 
operator as follows: 

M, Xj (= v(tj)), Wj (= v(hj)) |= B, if 0<i<x and 0<y'< y 

M, T, w 1= Rt:hB iff { 

1 1 J 

for all (t’,w’) in TxW with x’^r’ and w’A w’: 

M, x’, w’ |= B , otherwise; i.e. if x < i or y < j 

M, Xj (= v(tj)), w |= B, if 0 < i < x 

M, x, w |= RtjB iff { 

for all x’ in T with x’ ^ x’: M,x’,w |= B, 

otherwise; i.e. if x < i 

M,x ,w |= N la 'B iff for all x’ in T: M, x’, w\= B 

M,x ,w |= N lg B iff for all w’ in W: M, X, w’ |= B 

M, X, w |= OB iff for all x’ in T and all w’ in W: M, x’, w’ |= B. 

The truth conditions for sentences having the possibility operators M ,at , M lg and <> 
as their main connective are obtained in the dual way: just replace ‘all’ by ‘some’ to 
the right of the ‘iff in the last three conditions! 

As usual, then, we say that sentence A is Rxy-valid iff M, X, w |= A for all Rxy- 

models M, all x in T and all w in W. And we say that a set T of sentences is Rxy- 

satisfiable iff there exists a Rxy-model M with members x of T and vv of W such that 
for all sentences A in T: M, X, w |= A. 

Remark. Consider the truth condition for sentences of the form RtjB, the case where 0 
< i < x. It looks simple and straightforward enough, but the impression of simplicity 
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is really deceptive, because the condition harbours a hidden complexity that can be 
spelled out as follows. Recall that w is to be a member of W = [w 0 , w v ...,w } through- 
out the above truth definition. For the case we are considering this means that the 
truth condition for Rtf is to be split up into the following series of conditional truth 

conditions, whenever 0 < i <x: 

If xv = w 0 , then M, T, w |= Rtf iff M, T ; , w 0 |= B [iff M, T, xv |= Rtf 0 B] 

If xv = w v then M, T, xv |= Rtf iff M, T ; , w l |= B [iff M, T, xv |= Rtff] 

If w = w ; , then M, T, xv 1= Rtf iff M, T,, w ; 1= B [iff M, x, xv |= Rtff] 

J It 1 J I 1 1 J 

If w = w y , then M, T, w |= Rt-fi iff M, T ; , w y |= B [iff M, T, w |= Rtfi^B]- 

We see that the bracketed ‘iff -clauses are immediate by our truth condition for 
RtJiB, the case where 0 < i < x and 0 < j < y. A further observation is now to the ef- 
fect that the above series, or conjunction, of conditional truth conditions is in fact 
equivalent to the following categorical truth condition for Rtji, where the right mem- 
ber has the form of a disjunction: 

M, T, w |= RtjB iff either (w = vv 0 and M, T, w |= Rtj-i^fi) 



or 


(w = w l 


and 


M, x, xv j 


= Rtf ! B ) 


or 










or 


(w = w j 


and 


M, T, XV | 


II 

>3 


or 










or 


(w = W v 


and 


M, X, xv 


1= Rtf y B) 



Again, this categorical truth condition can be written more compactly as: 

M, X, w |= RtjB iff v 0 S / - s y (\v = xv j and M, T, w |= Rt/tjB) 

where the initial prefix in the right member of the equivalence may be replaced by an 
existential quantifier ‘for some natural number j with 0 < j <y’, since we are dealing 
with a finite set. 

The complexity just pointed out will reappear in the form of the “definitional” 
axiom schema A3(a) in Section 4 as well as in the proof of the so called Coincidence 
Lemma 5.3 in the Appendix infra. See also our discussion of the matter in the Intro- 
duction supra. 



4 On the Proof Theory of Two-Dimensional Temporal Logic 
with the R t and R th Operators: The Axiomatic Systems Rry 

The infinite hierarchy of axiomatic systems Rxy (x, ye (O) is determined by one rule 
of inference (deduction), one rule of proof, and five groups of axiom schemata. They 
are as follows, where the letters T and ‘/ range throughout over the set co of all the 
natural numbers, and where a notation like ‘v 0 S/ . £ yRtfijA’ [‘a 0 £ ; £ x Rtfi-] abbreviates 




12 Lennart Aqvist 



the finite disjunction ‘Rtfi^A v RtjhjA v ... v Rtf h’ [ the finite conjunction ‘ Rt 0 hjA a 
RtfijA a ... a RtJijA ’ ], with j running from 0 to y [i from 0 to x]: 

Rule of Inference 

mp (modus ponens) 

A, A^B 
B 

Rule of Proof 

Nec (necessitation for □) 

M 

| — C3A 

Axiom Schemata 

AO. All truth-functional tautologies over Sent 

A1 . (a) a { a £> ■ a A — » RtjhjA, for all i, j such that 0 < i < x and 0 < j < y 

(b) Rt j hj(a j a bj), for all i, j such that 0 < i < x and 0 < j < y 

(c) Rtfij-L, if x<i or y<j 

(d) a 0 v rtj v...v a x 

(e) b 0 v b ] v...v b y 

(f) G- — ^ — i cij, if i ^ j 

(g) b i^> -'bj, if iAj 

(h) — i cij, if x < i 

(k) -bj, if y < j 

(m) — > N tg a j (all i e of) 

(n) bj —> N ,a 'bj (all ye of). 

A2. (a) A^RtjhjA, for all i, ye 0) 

(b) RtJifA —> B) —> (RtJijA RtJijB), 

(c) RtfijA — > HRtjhjA 

(d) — iRtjhj — A — > RtjhjA .. 

(e) RtfijA — ¥ —i Rtfij—A, for all i.j with 0 < i < x and 0 < j < y 

A3, (a) RtjA <-» v os j< y (bj a RtjhjA), if 0 < ; < x 

(b) RtjA, if x < i 

A4. (a) A— >lV to A; OA — > N lg A 

(b) A N lat N lg A\ OA<r^N lg N la, A 

(c) The modal logic S5 for each pair of operators (□,<>), ( N ,at , M lal ) 





and (N lg , M lg ) 




(d) 


a j~* (N ,g A <-» A o<j< v RtjhjA), 


for all i e 0) 


(e) 


bj^> (N lat A ^ A 0iiix RtjhjA), 


for all j e 0) 


(f) 


□A <-> A Q < ; < v Ag <y< y RtjhjA 
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As usual, the above axiom schemata and rules determine syntactic notions of Rxy- 
provability and R xy -deducibility as follows. We say that a sentence A is R xy-provable 
[in symbols: | — Ryy A, or just | — A] iff A belongs to the smallest subset of Sent 
which (i) contains every instance of AO, Al(a)-(n),...,A4(a)-(f) as its member, and 
which (ii) is closed under the rule of inference mp and the rule of proof Nec. And we 
say that the sentence A is Rxy-deducible from the set T (cz Sent) of assumptions [in 
symbols: F | — Ryy A] iff there are sentences If B k in T, for some natural number k 
> 0, such that | — Rxy (fij a ... a B k )—> A (i.e. the sentence (B y a ... a Bf)—> A is to be 
Rrv-provable in the sense of the preceding definition). 

Again, letting T cSent, we say that T is R xy -inconsistent iff F | — Rvy _L , and R.rv- 
consistent otherwise. Finally, we say that T is maximal Rxy-consistent iff T is Rxy- 
consistent and, for each A in Sent, either A g T or —A g T ; where this latter condition 
is known as requiring T to be negation-complete. 

Soundness Theorem 4.1 

Weak version : Every R xy-provable sentence is R xv-valid. 

Strong version: Every Rxy-satisfiable set of sentences is Rxy-consistent. 

Proof. As usual, we establish the weak version by showing (i) that every instance of 
the axiom schemata AO, Al(a)-(n),...,A4(a)-(f) is Rxy-valid, and (ii) that the rules mp 
and Nec preserve Rxy-validity. This is tedious, but entirely routine. 

As to the strong version, it is easily obtained as a consequence of the weak one. 
Again, we rehearse a few obvious results on our infinite hierarchy Rry (x, ye co) in 
the following 

Lemma 4.2. (Scott’s Rule for Rvy; Fresh Properties of Maximal Rrv-Consi stent Sets; 
Lindenbaum’s Lemma for Rrv). Let § be any of the operators Rtfij ( i , j e co), N lar , 
N lg , □ ( all of which are ‘necessity modalities’ in a straightforward sense). Then: 

(I) Let r be a set of sentences and let A be a sentence. If T | — R A, then 

{ §B: fie T ) | Rtv §A. 

(II) Let r be any maximal Rxy-consistent set of sentences. Then it holds that: 

(i) a t G r, for exactly one natural number i such that 0 < i < x. 

(ii) bj G r, for exactly one natural number j such that 0 <j < y. 

(III) For any Rxy-consistent set T of sentences, define the Lindenbaum extension 
T w of r in the appropriate way. Then T (n is maximal Rxy-consistent. 

Proof. As for (I), this is familiar - see e.g. Makinson (1966) or Aqvist (1991), 
Lemma 6.5. As for (II), we argue as follows. By a well known property of maximal 
Rrv-consisterit sets, the disjunction A 1(d) is in T. Hence, by another such property, at 
least one of its disjuncts must be in T. Hence the existence part of clause (i). The 
uniqueness of ’that’ disjunct is then immediate by axiom A 1(f) supra. The proof of 
clause (ii) is similar: just appeal to Al(e) and A 1 (g). Finally, the proof of (III) is 
familiar as well. I 
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Lemma 4.3 (Useful Properties of the Operators Rt r Rtf- and N lat , 

(I) For all natural numbers x, y it holds that all instances of the following theorem 
schemata are Rxy-provable: 

TO. bj — » (RtjA <-» RtfjA) for all/, ye co such that 0 <i< x and 0 <j < y 

Tl. Rtj(A —>/!)—» (RtjA — > Rtf ) for all / with 0 < i < x 

T2. Rtf t ) — R / — A ■■ 

T3. Rtf N^Rtfi (0 < i < xf, Rt-A M la 'RtA (0<i<x) 

T4. bj -> (A ,fl 'A -> RtfjA) (0 < / < x; j g 

T5. bj — > (RtfijA — > M ,at A) (0 </<x; je (d) 

T6. — > (M la 'A 4->v 0 < £ fttfijA) (j e co) 

T7. .Rryl <-> Rtftfi for all i, k e <y with 0 <i,k< x. 

(II) In spite of the provability/validity in Rxy of TO, there are instances of the schema 

RtfijA — y RtjA 

which fail to be provable/valid in Rxy. ( Similarly for the converse of that 
schema . ) 

Proof. As to (I), the proofs in Rxy of the theorem schemata TO - T7 amount to useful 
exercises in the axiomatics for Rxv that are left to the reader. As for (II), the task of 
constructing counterexamples to both directions in TO-without-the-antecedent-/^ can 
be left to the reader as well. 

5 Canonical Rxy-Structures and Semantic Completeness 
of the Logics Rxy 

Definition 5.1. For any natural numbers x, y e OX let Qxy be the set of all maximal 
Rry-consistent set of sentences. Let q be a fixed element of Qxy. Furthermore, let 
~lat/~lg/ be the binary relation on Qxy such that for all u, v in Qxy: u ~lat v lu ~lg vl 
iff for each A in Sent, if N ,a ’A /N^A/ e u, then A e v. Again, let ~ be the binary rela- 
tion on Qxy such that for all u, v in Qxy: u ~ v iff for each A in Sent, if IDA e u, then 
A g v ; . Clearly, by the S5-properties of the operators N 1 "', N lg and □ [axiom schema 
A4(c) supra], the relations ~lat, ~lg, and - are equivalence relations on Qxy. 

We now define the canonical Rxy-structure generated by q as the ordered sextuple 
M‘i = (U, (m 0 , e 0 , n 0 ), ({t,} ;6W , x), ({w y .} y . 6W , y), V, v) 

where: 

(i) U = {u g Qxy: for each sentence A, if DA g q, then A g m}, i.e. 

U = {u g Qxy: q ~ u] = [ q]~ (i.e. the — equivalence class of q in Qxy). 

(ii) u Q = {A: Rt 0 hoA e q] 

e 0 = {A: RtfoA g q] 

n 0 = {A: Rtfif) g q] 
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{u g Qxy. {A: Rtf^A g q) ~lg w}, if 0 < i <x 

(iii) For each i g co : T ; = { 

0, otherwise, i.e. if x < i 

where x is the first natural number under consideration. 



{u g Q xy. [A: Rt Q hjA g q} ~lat u], if 0 <j < y 



(iv) For each j ear. Wj= { 

0, otherwise, i.e, if y < j 

where y is the second natural number under consideration. 

(v) V = the function such that for all p in Prop: V(p) = {(t ; ., w.): 0 < i < x, 0 < j < y, 
and there is exactly one u in U with u g T- n Wj and p e u } . 

(vi) v = the function on NT u NF1 defined as in Section 3 supra. 



Remark. Assume that 0 < i < x and 0 < j < y. By condition (iii), T = {T 0 , T 1 ,...,T V } is 
identified with a certain set of ~lg-equivalence-classes of members of Qxy, and, by 
condition (iv), W ={w 0 , w v ..., w } is identified with a certain set of ~lat-equivalence- 
classes of members of Qxy. 

We can now state two basic results concerning generated canonical Rxy-structures. 

Theorem 5.2. ,4.v defined in Definition 5.1 above, the initial quadruple in M q is a 
Rxy -frame, and hence M q as a whole is a R xy-model. 

Proof. See the Appendix of Aqvist (2004). I 

Coincidence 4 Lemma 5.3. Let q be any fixed maximal R xy-consistent set of 
sentences, and let M q (as above ) be the canonical R xy-structure generated by q. Then, 
for each sentence A and each u in U, 

M q , [«]~lg, [i/J-lat |= A iff A g u. 

Here we use the following familiar definitional abbreviations: [u]~lg = {v g U: u ~lg 
v} and [M]~lat = {v g U: u ~lat v}. Note also that the first set belongs to T and the 
second to W. (In order to verify that this is indeed so, just appeal to the fact [Theorem 
5.2] that M q satisfies the partition conditions (iii:a)-(iii:b) /(iv:a)-(iv:b)/ on Rxy-frames 
in Section 3, to the definition of T ; /w, / in Definition 5.1 above, and to elementary 
properties of equivalence relations.) 

Proof. By induction on the length of A. For details, see the Appendix of Aqvist 
(2004). I 



Completeness Theorem 5.4. 

Weak version : Every R xy-valid sentence is Rxy-provable. 

Strong version : Every Rxy-consistent set of sentences is Rxv-satisfiable. 



4 The word “Coincidence” used in the name of this Lemma is meant to suggest that, as applied 
to any sentences (of Rxy), the notions of truth and membership coincide, or are co-extensive, 
with respect to the points in generated canonical Rxy-structures. 
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Proof. As the weak version is immediate from the strong one, let us concentrate on 
the latter. Let T be any Rxy-consistent set of sentences. Form the Lindenbaum 
extension T of T: by Lemma 4.2 (III), Y r) is maximal Rxy-consistent. Again, form 
the canonical Rxy-structure generated by T ^ i.e. the structure M rco as defined in 

Definition 5.1 supra: by the basic Theorem 5.2, then, M Tm is a Rxy-model. By the 
Coincidence Lemma 5.3 for generated canonical Rvv-structures, we obtain in 
particular that for each sentence A: 

M T ", [rj-lg, [rj-lat \= A iff A e r ffl 

since Y 0) is known to belong to the universe U of M Tm . Hence, since T c Y 0) , we have 
M T<0 , [TJ-lg, [TJ-lat |= A for every A g r. In other words, assuming r to be any 
Rvv-consistent set of sentences, we have constructed a Rxy-model, viz. M r ®, with 
members t of T and w of W, viz. [TJ-lg and [ TJ-lat, such that for all sentences A in 
r : M Fw , T, w |= A. Hence, we have shown Y to be Rxy-satisfiable, as desired. 

6 Introducing Historical Modalities: 

The Systems HRxy and Their Semantics 

Syntax of HRxy. Let us add to the vocabulary of the systems Rry a pair of primitive 
one-place modal operators, N and M, to be read respectively as 

‘it is necessary on the basis of the past and the present that’, and 

‘it is possible on the basis of the past and the present that’ . 

Call the resulting language that of the systems HRvv (of two-dimensional temporal 
logic with the Rt and Rth operators and with historical necessity), where, as usual, x, y 
are any members of the set to of natural numbers. The definition of the set Sent of 
well formed sentences of HRvv is then obvious: Sent will be closed under the two 
new one-place connectives as well. 

Semantics for HRxy. Consider any Rrv-frame as described in Section 3 supra. We 
lay down a few preliminary definitions. First of all, observe that for each uinU there 
is, by conditions (iiira) and (iii:b), exactly one T in T such that u g t, as well as, by 
(iv:a) and (iv:b), exactly one w in W such that u g w. Define for all u, v in U: 
lg (m) = the T g T: u g x 

lat(w) = the w g W: u g w 

u -lg v iff lg(u) = lg(v) 
u ~lat v iff lat(«) = lat(v) 

where the function lg/lat/ is to mean the longitude / latitude / of, and where the binary 
relation -lg / -lat/ means is on the same longitude / latitude / as. (On the present 
general definitions of the relations -lg and -lat - ‘general’ in the sense of applying 
to all Rev-frames, not just to the initial quadruple in M‘i of the preceding section - 
these two relations are equivalence relations on U, so we are still entitled to use the 
standard notation for equivalence classes, i.e. ‘[ ]~lg’ and ‘[ ]— lat’.) 
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Again, since any Rxy-frame satisfies the condition (v) in Section 3, we can define 
the following function / from TxW into U. For each X in T and each w in W: 

fix, w) = the u in U\ {«} = x n w 
i.e. fix, w) is identical to the sole member of the intersection T n w. 

HRxy-Frames. We now take a HR xy -frame to be the result of adding to any Rxy- 
frame a binary equivalence relation ~ on U satisfying the following conditions, for 
all u, v in U: 

(Cl~) If u ~ v, then u ~lg v. 

(C2~) If u 0 ~lg u, then u Q ~ u. 

Moreover, ~ is to satisfy, for all integers i, k such that 0 < k< i < x and all integers j, 
m with 0 < j, m<y: 

(C3=) If fix, Wj ) -fix, w m ), then fix k , Wj ) ~fix k , wj. 

Remark. The intuitive import of the relation ~ is this: we have u ~ v iff (i) lg (u) = 
lg(v), i.e. the time of u is identical to the time of v, and, moreover, (ii) lat(w) and lat(v), 
i.e. the histories to which u, v respectively belong, share the same past and present up 
to and including the time which is common to u and v; in other words, lat(M) and lat(v) 
are to ‘coincide’ at the time lg(w) |=lg(v)] and at all times in T previous to lg(«). 
Hence, (Cl~) requires the equivalence relation = to be, for any u in U, a relation on 
the ~lg-equivalence class [w]~lg (= {v e U: u ~lg v}). Furthermore, (C2~) 
guarantees that the ~lg-equivalence class [w 0 ]~lg can be taken as the origin of the 
finite tree which is definable on any HRxy-frame by means of =. Finally, (C3~) is a 
characteristic condition on =, leading to the representation of time by such a tree. In 
the suggestive terminology of Zanardo (1985), we may say that (C3~) requires 
fix,Wj) ~ fix ,w m ) to hold only if the (strict) pasts of fix,Wj) and fix,w m ) ‘coincide 
modulo =’. 

HRxy-Models and Truth Conditions. We now take a valuation on a HRxv-frame 
still to be any function V from Prop into the power-set of TxW. In accordance with 
our informal characterization of ~ just given above, we then require V to satisfy the 
following condition, for all p in Prop and all u,v in U: 

(C4~) If u ~ v, then ([«]~lg, [«]~lat) e V(p) iff ([v]~lg, [v]~lat) e V(p). 

As usual, then, we mean by a HRxy-model any ordered triple 

M = ( F , V, v) 

where the first term is a HRx v-frame, the second a valuation on that frame, and where 
v is as in Section 3 supra. In the extended truth definition relative to HRxv-models we 
now have the following truth condition for sentences of the form NB: 

M, T, w |= NB iff for all w’ in W such that/(T, w) - fix, w ’): M, T, w’ |= B\ 
and dually for MB. 

Finally, the notions of HR xy-validity and HRxv- satisfiability are straightforward. 
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7 Proof Theory of Two-Dimensional Temporal Logic 
with the R t and R th Operators and Historical Necessity: 

The Axiomatic Systems HRxy 

Each axiomatic system in the infinite hierarchy HRxv (x, y e CO) still has mp as its 
sole primitive rule of inference and Nec (for □) as its sole primitive rule of proof, but, 
in addition to the five groups AO, Al(a)-(n),...,A4(a)-(f) of axiom schemata, it has a 
sixth group of axioms governing the new modalities A and M, viz. the following: 

A5. (a) N lg A — » NA; MA — » M lg A 

(b) Rt () h 0 NA Rt () h 0 N Ig A 

(c) The modal logic S5 for N and M 

(d) p — » Np, for all p in Prop 

(e) wNA — » NwA. 

(f) Rt in NA — > Rt j NRt j /t A, for all i, n e (O with 1 <n<i<x 

Remark. In the next to last axiom, A5(e), there occurs a one-place operator w [“at 
the last point west of here on this latitude’’, “yesterday”] used already in Aqvist 
(1999): Section 11, which can be defined in our present framework in terms of the 
systematic frame constants a. and b. together with the realization operators Rth. 
as follows: 

Def.w. wA ^ df v 0 <■ < y (bj a (a 0 v v 0 < < fa t a Rt iA hjA))) 

where the v-notations denote certain finite disjunctions in the familiar way. 

The definitions of the notions of provability, deducibility, consistency and maximal 
consistency for H Rat are straightforward. 

Soundness Theorem 7.1 and Lemma 7.2 

Both versions of the Soundness Theorem 4.1 are readily extended to the logics HRxv. 
In like manner, Lemma 4.2 is easily extended so as to apply to the fresh hierarchy of 
systems HRxv. 

For instance, in the validation of Scott’s Rule for HRxv [clause (I)] we allow for the 
case that § = N. Further details are left to the reader. 

Let us list some useful properties of the defined operator w in the following 

Lemma 7.3. (i) A.? defined by Def.w, this is a derived rule of proof both in HRxv + 
Def.w and already in Rry + Def.w, where, for the sake of expository simplicity, we 
write just ‘| — ’ to indicate provability in the relevant system'. 

w-necessitation: from \ — A to infer \ — wA. 

Moreover, (ii) all instances of the following theorem schemata are provable in Rrv + 
Def.w as well as in HRxv + Def.w: 

Tl. N la, A — » wA 

T2. a. — » (wA — > — iw— A), for all integers i such that 1 < i < co 

T3. w(A — > B) — > (wA — ¥ wB). 

Proof. Ad w-necessitation. To derive this rule of proof in the system at issue, use the 
primitive rule of proof Nec (= necessitation for □) together with axiom schema A4(a) 
and the fresh theorem schema T 1 just stated. 
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Ad Tl. Use various axioms under Al, A2 and A4 [notably A4(e)] together with 
Def.tv! 

Ad T2 and T3. Similarly. I 

Lemma 7.4 (Properties of the New Operators N, M). 

(I) For all natural numbers x, y it holds that all instances of the following 
theorem schemata are HRxy-provable: 

T4. RtNA RtNRt A for all i e 0 ) such that 0 < i < x 

T5. Rt^fJRtjA — > RtflRtfi for all i, n e co with 1 < n < i < x 

T6. Rtp — > RtfJRtp for all i e co with 0 < i < x and all p in Prop 

(II) None of the following sentence schemata are HRxy-provable or HRjcy -valid: 

(a) bj — > Nbj (0 <j<y) 

(b) RtjA — > NRtA (0 < i < x) [in contrast to T3 in Lemma 4.3 (I)] 

(c) NA N'sA 

(d) NA — > N ,a 'A 

(e) NA — > DA 

(f) N la 'A NN la, A 

(g) M lat A NM la, A 

(h) Rt jn NA — > RtNA, for all i, n e to with 1 <n<i<x 

(k) Rt t _ n A — > RtjNRtj tI A, for all i, n e 0 ) with 1 <n< i<x 

(II) In the spirit of Aqvist & Hoepelman (1981), Section 12: Theorem 2, axiom 
A5(d) [p — > Np, for p in Prop] can be generalized so as to yield the 
following theorem schema o/HRat: 

T7. A — > NA, provided that A contains no occurrences of the operators Rt-, N h ", 
or M lar or of any frame constant bj ( 0 < / < co). 

Proof. As to (I), the proofs in HRvy of the theorem schemata T4 - T6 amount to 
exercises left to the reader, somewhat tedious in the first case. [We observe that 
analogues of T4 and T5 are taken as axioms in Bailhache (1991), Ch.IV, p. 74 f., and 
that an analogue of T6 is discussed by the author in the very same context.] As for 
(II), we leave to the reader the task of constructing appropriate counterexamples to the 
HRvy- validity of the schemata (a) - (k). [Note that the schemata (h) and (k) are 
analogues of van Eck’s Thl and Th2 on p. 280 in the Logique et Analyse 25 (1982) 
version of van Eck (1981 ).] As for (III), the proof of T7 is by an easy induction on the 
length of A. In the basis we appeal to A5(d), A5(a) and Al(m). For the interesting 
cases in the induction step, we use inter alia A4(a), A4(c), A5(a), A5(c) and A2(c). 



8 Semantic Completeness of the Logics HRry 

Preliminaries: Generated Canonical HRxy-structures. We begin by extending 
Definition 5.1. So the canonical HRxy-structure generated by any fixed maximal 
HRyy-consistent set of sentences q will be the ordered septuple 

M‘i = (U, (k 0 , e 0 , n 0 ), ({T ; } ;e(tf , x), ({w-} ]e0J , y), ~ V, v) 
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Where 

(i) U = {u e f2 HR xy: for each A in Sent, if OA e q , then Ae «] 

(with L2 hr at being the set of all maximal HRxv-consistent sets of sentences) 
and where the remaining conditions (ii)-(vi) now apply to U in this new sense and to 
the set Sent of sentences in our expanded language of HRxy. Moreover, there will be 
the following fresh condition governing our new equivalence relation =: 

(iv ~) ~ is the binary relation on U such that for all u, v in U: u ~ v iff for each A in 
Sent, if NA e u, then Ae v. 

Theorem 8.1. As defined in the extended Definition 5.1 just presented , the initial 
quintuple in M q is a HR xy-frame and M q as a whole is a URxy-model. 

Proof. See the Appendix of Aqvist (2004). I 

Furthermore, for q and M q as above and for all A in Sent and u in U, we have the 
following extended 

Coincidence Lemma 8.2. M q , [u]~ lg, [«]~lat |= A iff A e u. 

Proof. See again the Appendix of Aqvist (2004). I 

Finally, as a consequence of the last two results, we obtain the following 

Completeness Theorem 8.3 for HRxy. Both versions of the Completeness 
Theorem 5.4 are extended so as to apply to the new hierarchy of logics HRxy. The 
pattern of argument remains the same as in the case of the Rat: in addition to the 
results 8.1 and 8.2 we use Lemma 7.2 (= Lemma 4.2 as extended to HR at) in the 
proof. I 



9 Extending the R/R t ], Logics of Historical Necessity 
to Dyadic Deontic Logics of Conditional Obligation 
and Permission: Syntax and Semantics for the Systems DHRxym 

Syntax of the Systems DHRxym. In this and the following sections we deal with an 
infinite hierarchy DHRxym of logics combining dyadic deontic modalities with the 
temporal ones so far studied in this essay, where, as usual, x, y are any members of 
the set co of natural numbers, and where m is any positive integer with 1 < m < y+ 1 . 
Those logics are based on a common formal language obtained by our adding to the 
vocabulary of the earlier systems HRxy the following items: 

(i) A third infinite family of systematic frame constants, viz 

{ Qk'i k=\ 2 indicating various ‘levels of perfection’; as well as 

(ii) a pair of dyadic deontic modalities, O (for conditional obligation) and P (for 
conditional permission), the readings of which will be considered in a 
moment. 
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The definition of the set Sent of well formed sentences of DHRxym is then 
straightforward: all the new frame constants will be (atomic) sentences; moreover, 
whenever, 4, B are sentences, so arc OgA and P t A . 



Remark on Notation for Dyadic Deontic Operators. We write 0 ; A [P h A | in order to 
render the ordinary language locution “if B , then it ought to be that A” [“if B, then it 
is permitted (permissible) that A”]. We prefer this style of notation to the current one 
0(A/B ) [P(A/B) ], because (i) it is paranthesis-free, and (ii) the reading goes from left 
to right, and not the other way around. 

Semantics for DHRxym: A General Remark. Our presentation of the semantics for 
DHRxym will differ from the one given in the cases of Rxy and HRxy in the 
following crucial respect. In those earlier cases we started out by defining (1) the 
notion of a frame , then (2) that of a model (using the concept of a valuation on a 
frame), whereupon we gave (3) a recursive definition of the notion of truth relative to 
a model, in terms of which, finally, (4) we could characterize the notions of validity 
and satisfiability. For reasons that will hopefully appear as we go along, we have to 
change the terminology a bit and adopt another order of progression in the present 
case of DHRxym: we start out by defining (1) the concept of a structure, which 
already includes that of a valuation (on a frame) and which enables us to give (2) a 
recursive definition of the notion of truth relative to a structure, whereupon (3) we 
introduce the concept of a model as a special kind of structure, in terms of which (4) 
we characterize the notions of validity and satisfiability. 



Semantics for DHRxvrn: DHRxym-structures. Let x, y e CO and let m be any 

positive integer with 1 < m < v+1 . By a DHRxym-structure we shall mean a sequence 



M = ((U, (m 0 , e 0 , n 0 ), ({t,}, 6W , x), ({vv ; } ;e()J , >■), «, V, v), ({ opt jt } fc=1 2 

where: 



m )> Sent) 



(i) The initial septuple is a HRxv- model. 

(ii) {opt^J^jj is an infinite sequence of subsets of U [to be thought of as 
representing levels of perfection ], and m is the positive integer < v+1 under 
consideration. 

(iii) {Rgl^gx^, is a family, indexed by Sent, of binary relations on U. 



We can now tell what it means for any sentence A to be true at a time xe T = [t 0 , 
Tj,..., x x ] in a history we W = [w 0 , w v ...,w y ] relative to any DHRxym-structure M. Our 
extended truth-definition will contain two fresh clauses, one governing atomic 
sentences Q k , and one governing dyadic deontic sentences of the forms 0 B C and 
P B C: 

fix, w) e opt^, if 1 < k < m 

M,x,w |= Q k (k= 1,2,....) iff { 

X T, otherwise, i.e. if m < k 

M, t, w |= 0 B C iff for all w’ in W such that/(x, w) R b /(t, w’): M, t, w’ |= C 

M, x, w |= P B C iff for some w’ in W with fix, w) R B fix, w’): M, T, w’ |= C. 
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Semantics for DHRxym: DHRxym-Models 

We now focus our attention on a special kind of D H Rxyn (-structures called 
‘DHR xym-models’ . So by a DHR xym-model we shall mean any DHRvyni-structure 
M, where [opt A ], m and {R B } satisfy the following three additional conditions: 

81 [Exactly m Non-Empty Levels of Perfection]. This condition requires the set 
[optj, opt 0 ...... °pt m } to be a partition of U in the sense that 

(a) opt ; n opl^ = 0 , for all positive integers i, j with 1 < ijtj < m 

(b) opt! U....U opt m = U 

(c) opt /f -t 0, for each positive integer k with 1 < k < m 

(d) opt A = 0, for each positive integer k with m< k < co. 

The second condition on DHRxym-models requires M to be such that for all u, v in U 
and any integer k with 1 < k < m: 

82 [Closure of the opt /( under ~lat]. If u e opt A and u ~lat v, then v e opt /f . 

Clearly, 82 requires each opt /( with 1 < k < m to be closed under the relation ~lat of 
being on the same latitude as. 

Our third, crucial condition on DHRyym-models pertains to the indexed family 
{RfllseSent’ requires any u, v in U and any sentence B to be such that: 

S3 [Import of the relations R fi ]. u v iff u~v and M, [v]~lg, [v]~lat |= B and for 
each z in U with u~z and M, [z]~lg, [z]~lat |= B it holds that v > z. 

Here, the weak preference relation >, “is at least as good (ideal) as”, is to be 
understood as follows. First of all, by clauses (a) and (b) in the condition 81 [Exactly 
m Non-empty Levels of Perfection], we have that for each u in U there is exactly one 
positive integer k with 1 < k < m such that u e opt A . We then define a ‘ranking’ 
function r from U into the closed interval [1, m] of integers by setting, for each u 
in U : 



r (u) = the k, with 1 < k < m. such that u e opt A . 

Finally, define > as the binary relation on U such that for all u,v in U: 

u > v iff r(«) < r(v). 

Validity and Satisfiability in DHRxym. Armed with the notion of a DHRxym - 
model, we then introduce the notions of DHR xym-validity and DHR xym- satisfiability 
in the same way as we defined the corresponding notions for the logics Rxy and 
HRi'v. See Section 3 supra. 
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10 Proof Theory for the R/R t h Logics of Historical Necessity 
with Conditional Obligation and Permission: 

The Axiomatic Systems DHRxym 

Each axiomatic system in the infinite hierarchy DHRxym (x, y, m e ft), 1 < m < y+1) 
still has modus ponens (mp) as its sole primitive rule of inference and Nec (for □) as 
its sole primitive rule of proof. In addition to the six groups of axiom schemata AO, 
Al(a)-(n),..., A4(a)-(f) [Section 4 supra ] and A5(a)-(e) [Section 7 supra], DHRxym 
has a seventh group of axiom schemata governing the new frame constants Q k (with 
k= 1,2,....) and the new dyadic deontic modalities O and P, viz. the following: 

A6. (a) Q x v Q 2 v .... v Q m 

(b) Qj — > —i <2, for all i,j in co with 1 < i Aj < co 

(c) M'sQ { a M'sQ 2 a .... a M'sQ m 

(d) Q k — > N ,a ’Q k , for all k in co with 1 < k<m 

(e) P gA Cr- > — 'Ob — ^ 

(f) O b (A — > C) — > (OgA — > 0 B C) 

(g) OgA NOgA 

(h) NA -> OgA 

(i) N(A^B)-^(O a C^O b C) 

(j) 

(k) 0 AaB C O a (B^Q 

(l) MA -4 ( O a B -> P a B ) 

(m) P a B -4 (O a (B C) -» aB C) 

(n) P A Q k — > (0. — » — iA), for all j, k in m with 1 <j<k< in 

(o) G[ — > (OgA — > (B — » A) 

(p) (Q^. a D^A a B a —A) — > P b {Qi v....v j), for all A: in ft) with 1< A:< m. 

(q) Rt j n OjA — > Rt / OjRt i ); A, for all i, n e ft) with I < n < i < x 

The definitions of the notions of provability, deducibility, consistency and maximal 
consistency for DHRxym are then straightforward. 

Soundness Theorem 10.1 

The Soundness Theorems 4.1 and 7.1 (both versions) are again readily extended to the 
logicsDHRxym. The detailed proof is left to the reader. I 

Lemma 10.2 

In like manner. Lemma 4.2 on our basic two-dimensional temporal logics Rxv with 
the R t and R th operators is extended so as to apply to the new hierarchy DHRxym. 
Thus, in the validation of Scott’s Rule for DHRxym [clause (I)] we allow for the cases 
where § = N, 0 B or P B . Moreover, in the extended Lemma 4.2 [clause (II)], we have 
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the following fresh subclause governing the constants Q k , where F is any maximal 
DHRxym-consi stent set of sentences: 

(iii) Q k e r, for exactly one positive integer k with 1 <k<m. 

In the proof of this subclause, we appeal to the axiom A6(a) in order to establish 
existence , and to axiom A6(b) in order to get uniqueness. 

Lemma 10.3 (Properties of the New Constants/Operators Q k , 0 B and P B ). All 
instances of the following theorem schemata are provable in DHRxym: 

T1 . — i Q., for all positive integers k with m <k< co 

T2. lfA — > NP,A 

T3. P b (A vC)h (PsA v P B C) 

T4. Rt-0 JitjA (0 < i < x ) 

T5. Kt i n Oj( Kt i n OjKtA — > RtkAjRt A ) (1 < n < i < x) 

Proof. Ad Tl. Suppose Q, for some k such that m < k < CO. Then, by axiom schema 
A6(b), we obtain — . Q v — . <2i and ... and — . Q , whence — . (Q l v...v Q m ), contrary to 
axiom A6(a). Hence, | — Q k — > _L and Tl, as desired. 

Ad T2. We first obtain MlfA — > If. A by contraposing A6(g), and then A'MIfA — > 
NPgA by familiar S5-principles [axiom schema A5(c) in Section 7], Since by A5(c) 
we also get IfA — > NMIf A . the desired result T2 is immediate. 

Ad T3. Immediate by axioms A6(e), (f) and (h) together with the underlying logic 
of N. 

Ad T4. Exercise (easy, though somewhat tedious). Use inter alia A4(d)! 

Ad T5. Assuming Rt i n OjRt i A, we obtain by A6(q) RtfJjRtf ll Rt j A . and by T7 in 
Lemma 4.3 supra [enabling us to reduce the compound Rt i _ n Rt i to Rt] RtfJjRtf . So 
we get | — Rt j JJjRtA — > RtfjjRt^A by the Deduction Theorem for DHRxym. 
Applying the easily derived rule of proof : 

from | — A to infer \ — Rt k _ n OjA (1 <n<i<x ) 

to this last result, the desired conclusion T5 is immediate. 

Remark 1. The above theorem schemata T1-T3 will be explicitly appealed to in the 
proof of Theorem 11.2 infra, which is an essential ingredient in our Completeness 
Theorem 11.3 for the systems DHRxym; see the Appendix below. More precisely, we 
use them in showing that the canonical D H Rxy ; ; (-structure M c i [Section 1 1 infra] is 
indeed a DHRxym-model in the sense of satisfying the characteristic conditions 51 - 
53 in the semantics for those systems. 

Remark 2. The theorem schemata T4 and T5 are D H Rxy /; (-analogues of the axioms 
AOtl and AOt2, respectively, in Bailhache (1991), Ch.1V, p.81. Note that neither T5 
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nor A6(q) can be strengthened by replacing 0 T by 0 B (with arbitrary formula B) in 
those schemata. 

Remark 3. We observe that the axiom A6(c) can be - prima facie - weakened as 
follows: 

A6(c’) <kQ, a O0 2 A — a <O0 );l 

However, using axiom schemata A4(b)-(c) [Section 4 supra] together with A6(d), 
we easily derive our original formulation A6(c) from A6(c’). The derivation is left to 
the reader as an exercise. Thus, the two formulations are in effect equivalent in the 
axiomatics for DHRxym. 

Lemma 10.4 (DHRxym- Analogues of Results in Aqvist & Hoepelman (1981), 
Sections 15-16). All instances of the following theorem schemata are provable in 
DHRavot: 

T6. A — > NA; A — •> OgA , provided that A contains no occurrences of the 
operators R tj , N lat , or M Ia ', or of any frame constants bj (0 <j < CO) or Q k ( 1 < 
k< co). 



T7. 


( NA v N — A) — > (O t A A) 


T8. 


NA v N—A, 


where A satisfies the proviso of T6 


T9. 


OjA <r^A, 


where A satisfies the proviso of T6 


T10. 


0 j^A (B — > OjA), 


where B satisfies the same proviso 


Til. 


OfiA O-^B — > A), 


where B satisfies the same proviso 


T12. 


(B —> OjA) <rO Of B — > A), where B satisfies the same proviso. 



Proof. Ad T6. Easily handled in the spirit of the proof of T7 in Lemma 7.4 (III) 
supra. 

Ad T7. For NA ( OjA A), use AO, A5(c) and A6(h). For N—A — » (O t A A), 

use A5(c), A6(h), A6(l) [relying on | — MT] and A6(e). 

Ad T8. Use AO and T6 supra. 

Ad T9. Immediate from T7 and T8. 

Ad T10. For the left-to-right direction, assume O h A and B, where B satisfies the 
proviso of T6 [containing no occurrences etc.]. Then NB by T6 as well as N(B <-»T) 
by A5(c). Hence, O h A <->(9 T A by A6(i), so OjA and B —> OjA by AO. For the right- 
to-left direction, make the counterassumption that (B — > OjA) together with P B —A, 
where B still satisfies the proviso at issue. We then leave to the reader the task of 
showing that this counterassumption implies the contradiction that N—iB a MB. 

Ad Til. For the left-to-right direction, make the counterassumption that OgA a 
Pj( IS a— A). Show that MB follows from the second conjunct, and that OjA follows 
from the first one [the proviso gives us | — MB — > B and | — B — > (OjA OgA)], 
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whence Oj( B — > A) contrary to the second conjunct. The opposite direction is 
handled in the same spirit. Note that the axiom schema A6(j) is used in the proof of 
both directions! 

Ad T12. Immediate from T 10 and T1 1. 



11 Semantic Completeness of the Logics DHRjcjm 

Preliminaries: Generated Canonical DHRxym-Structures. We begin by extending 
Definition 5.1. For any natural numbers x, y, m e ft) with 1 < m < y+1. let Q Dm xym be 
the set of all maximal DHRvy/w-consistent sets of sentences. Let q be a fixed element 
of f3 DHR .rv/«. Define the canonical DHR xym-structure generated by q as the 
sequence 

M“ = ((U, (u 0 , e 0 , n 0 ), ({T f -} f - e „ x ), ({wj} je0) ,y), ~V, v), ({ opt /t } fc=1 2 , m), {R B } BeSent ) 
where 

(i) U = (be i2 DHR rym: for each A in Sent, if DA e q , then A e u) 

and where the remaining conditions (ii)-(vi) in Definition 5.1 now apply to U in this 
new sense and to the richer set Sent of sentences in our expanded language of 
DHRvv/w. Similarly for the condition (iv =) stated in the Preliminaries to Section 8 
above, which condition is still assumed to govern the equivalence relation =. 
Furthermore, we must define the remaining items in M q : 

(vii) °pt/.= {mg U: Q k e u } ( k= 1,2,...) 

(viii) m is the third natural number under consideration. 

Finally, as to the indexed family {R B }, we require each B in Sent to satisfy: 

(ix) R fi = the binary relation on U such that for all «, v in U: 

u R ;j v iff for all A in Sent: if O lf A e u, then A e v. 

Moreover, for canonical DHRYym-structures (generated by qe U) as just defined by 
conditions (i)-(iv),(iv ~),(v)-(ix), we introduce the ranking function r from U into the 
closed interval [ 1 , m] of integers by setting, for each u in U: 

r ( m) = the k, with 1 < k < m, such that Q k e u. 

This definition of r is clearly justified by our fresh subclause (iii) in Lemma 10.2 

(II). 

Again, > is the binary relation on U such that for all u, v in U: it > v iff r (u) < r(v). 

Having gone through these preliminaries, we now state two basic results on 
generated canonical DHRxym-structures. However, the order of presentation will be 
reversed as compared with the one adopted in Sections 5 and 8 supra, and similarly 
for their proofs given in the Appendix of Aqvist (2004). The reason for this reversal 
will again become apparent in that Appendix. 
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Coincidence Lemma 11.1. Let q be any fixed maximal DHRxym-consistent set of 
sentences, and let M q , as just defined, be the canonical DURxym-structure generated 
by q. Then, for each sentence A and each u in U: 

M q , [u]~ lg, [«]~lat |= A iff A e u. 

Proof. By induction on the length of A. For details, see the Appendix of Aqvist 
(2004). 



Theorem 11.2. ,4.v just defined, M q is a DHRxym-model. 

Proof. See again the Appendix of Aqvist (2004). 

As a consequence of the two basic results just stated, we obtain the desired 

Completeness Theorem 11.3 for DHRjcym. Both versions of the Completeness 
Theorems 5.4 and 8.3 are extended so as to apply to the new hierarchy of logics 
DHRxym. 

Proof. The pattern of argument remains the same as in the case of the Rxy and the 
HRav: just use right Lemmata/Theorems! 
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Abstract. In this paper we consider the relation between desires and obligations 
in normative multiagent systems. We introduce a model of their relation based 
on what we call the social delegation cycle, which explains the creation of norms 
from agent desires in three steps. First individual agent desires generate group 
goals, then a group goal is individualized in a social norm, and finally the norm 
is accepted by the agents when it leads to the fulfilment of the desires the cycle 
started with. We formalize the social delegation cycle by formalizing goal gen- 
eration as a merging process of the individual agent desires, we formalize norm 
creation as a planning process for both the obligation and the associated sanctions 
or rewards, and we formalize the acceptance relation as both a belief of agents 
that the fulfilment of the norm leads to achievement of their desires, and the belief 
that other agents will act according to the norm. 



1 Introduction 

The relation between obligations and actions is a classical field of study in deontic 
logic. However, when we consider actions of agents with beliefs and desires, then some 
questions arise which are traditionally not studied in this area. In agent theory, the rela- 
tion between desires and obligations has been formalized in BOID agent architectures 
as a combination of BDI agent architectures [10] and normative (BO) agent architec- 
tures, and more generally in normative multiagent systems (NMAS) as a combination 
of multiagent systems (MAS) and normative systems (NS) for applications like virtual 
communities [5]. Whereas BDI and NMAS conceptualize the agent’s decision making 
behavior in terms of goals and desires, BO and NS conceptualize the agent’s behavior 
in terms of obligations and permissions. 

BOID = BDI + BO NMAS = MAS + NS 

However, the proposed BOID architectures and normative multiagent systems do 
not explain how desires and obligations are related. Consequently, the formalization of 
desires and obligations has raised many questions. For example, is the logic of desire 
different from the logic of obligation [20]? How do agents deal with conflicts between 
desires and obligations in their decision making [1 1 ]? Why do agents often respect obli- 
gations even if they know that their violations are not or cannot be sanctioned? What 
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Fig. 1 . A : the social delegation cycle. 



does this imply for the rational creation of norms in such systems, and which mecha- 
nisms do not work properly without a normative system? How are social constructions 
like normative systems constructed from multiagent systems [27]? When is a separation 
of powers as in trias politica a necessary precondition for norm creation to be efficient? 

In this paper we introduce the social delegation cycle, which explains the creation of 
norms from desires from a rational (e.g., Kantian) perspective. We assume that norms 
are only accepted if they are respected by the other agents, and therefore sometimes 
sanctions are needed. Informally, it consists of three steps visualized in Figure 1 . Indi- 
vidual agents have desires, which turn into group (or joint, or social) goals. A group goal 
is individualized by a social norm. The individual agents accept the norm, together with 
its associated sanctions and rewards, because they recognize that it serves to achieve 
their desires the cycle started with. 

We study the social delegation cycle in a formal framework. The research questions 
of this paper are: 

1 . How to balance goal generation, norm creation, and acceptance? 

2. How to formalize joint goal generation? We formalize goal generation as a merger 
of individual desires. 

3. How to formalize norm generation? We formalize norm creation as a planning prob- 
lem, distinguishing between creation of the obligation and creation of the associated 
sanctions and rewards; 

4. How to formalize the acceptance relation? We formalize the acceptance relation 
by distinguishing between the fulfilment of the agents’ desires, and the belief that 
other agents will fulfill the norm. 

The conceptual model we use to study and formalize the social delegation cycle 
is based on a formal characterization of normative multiagent systems we have devel- 
oped elsewhere [5, 8, 9], which is based on rule based systems and input/output logics. 
Moreover, this other work is based on the assumption that the normative system can be 
modelled as an agent. This paper is not based on this assumption, but it is related to it, 
as we explain in detail in Section 9. 

The layout of this paper is as follows. In Section 2 we discuss the balance between 
goal generation, norm creation and acceptance. In Section 3 we define the conceptual 
model in which we study and formalize the social delegation cycle, and in Section 4 
we define the logic of rules. In Section 5 we formalize goal generation, in Section 6 we 
formalize norm creation, and in Section 7 we formalize the acceptance relation. 
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2 Social Delegation Cycle 

When developing a formal model for the social delegation cycle, we have to make two 
fundamental choices. 

- We may define a general model of the social delegation cycle, defining a range of 
possibilities, or we may define an actual procedure. The two are not exclusive, since 
we can first define a general theory of social delegation cycle, thereafter desirable 
properties within this framework, and finally procedures within the framework that 
satisfy some or all of the desirable properties. 

- We have to define how the elements of the social delegation cycle, i.e., goal gen- 
eration, norm creation and acceptance, are balanced. For example, strictly defined 
norm creation procedures only create norms that will always be accepted, and anal- 
ogously strictly defined goal generation procedures generate only goals for which 
a norm can be created that is accepted. 

In this paper, we propose a fairly general formal model of the social delegation cy- 
cle, which delimits the kind of norms that can be created, but that does not give an actual 
procedure to create norms. The reason is that we aim to capture the fundamental proper- 
ties of the social delegation cycle, which later can be used to design actual procedures. 
However, compared to informal characterizations of the construction of social reality, 
such as in the work of Searle [27], our model is fairly limited as we do not introduce 
for example beliefs or institutions. This issue is discussed in Section 10. 

Concerning the balance between the elements of the cycle, we do not aim to define 
strict goal generation and norm creation procedures. The reason is that we believe that 
our setting is more realistic and may cover a wider range of social delegation cycles. 
Moreover, it facilitates the use of formal theories developed elsewhere, such as merging 
theories for joint goal generation, planning theories for norm creation, and game theo- 
ries for acceptance. We consider the definition of strict mechanisms more relevant for 
the design of mechanisms of norm creation. 

Our model builds on several existing formal theories and formalizes the three steps 
as follows: 

Goal generation generates a set of goals based on merging operators, which have been 
proposed as generalizations of belief revision operators inspired by social choice 
theory. 

Norm creation creates for each goal a set of norms (or revisions of existing norms) 
based on planning theories as used in most theories in artificial intelligence. 
Acceptance relation accepts or rejects a norm based on game theories. We assume that 
norms are thus only accepted if they are respected, and we formalize the acceptance 
relation by distinguishing between fulfilment of the agents desire, and the belief that 
other agents will fulfill the norm. 

Before we present our formalizations, we define in the following two sections the 
conceptual framework we use based on rule based systems, and the logic of rules based 
on input/output logics. 
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3 Conceptual Model 

The conceptual model is visualized in Figure 2, in which we distinguish the multiagent 
system (normal lines) and additions for the normative system (thick lines). Following 
the usual conventions of for example class diagrams in the unified modelling language 
(UML), □ is a concept or set, — and — > are associations between concepts, and — E> is 
the “is-a” or subset relation. The logical structure of the associations is detailed in the 
definitions below. 




Fig. 2. Conceptual model of normative multiagent system. 



The model consists of a set of agents (A), which are described (AD) by a set of 
boolean variables ( X ) including decision variables it can perform and desires ( D ) 
guiding its decision making. The motivational state of the group (G) is composed of 
its goals. Desire rules can be conflicting, and the way the agent resolves its conflicts 
is described by a priority relation (>) that expresses its agent characteristics [11]. The 
priority relation is defined on the powerset of the motivations such that a wide range of 
characteristics can be described, including social agents that take the desires or goals 
of other agents into account. The priority relation contains at least the subset-relation 
which expresses a kind of independence between the motivations. Variables which are 
not decision variables are called parameters ( P ). 

Definition 1 (AS). An agent set is a tuple ( A , X , D , G, AD , >), where: 

- the agents A, variables X, agent desires D and group goals G are four finite dis- 
joint sets. We write M = D U G for the motivations defined as the union of the 
desires and goals. 

- an agent description AD : A — > 2 XyJD is a complete function that maps each agent 
to sets of variables ( its decision variables) and desires, but that does not necessarily 
assign each variable to at least one agent. For each agent a € A, we write X a for 
X n AD (a), and D a for D D AD(a). We write parameters P = X \ U aey rA' a . 

- a priority relation >: A — > 1 M x 2 M is a function from agents to a transitive and 
reflexive relation on the powerset of the motivations containing at least the subset 
relation. We write > a for > (a). 

Desires and goals are abstract concepts which are described by - though concep- 
tually not identified with - rules ( Rul ) built from literals (Lit). They are therefore not 
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represented by propositional formulas, as in some other approaches to agency [13, 25]. 
Agents may share decision variables, or desires, though this complication is not used in 
this paper. Background knowledge is formalized by a set of effect rules ( E ). 

Definition 2 (MAS). A multiagent system is a tuple (A, X, D,G, AD, E, MD,>), 
where (A, A", D , G , AD , >) is an agent set, and: 

- the set of literals built from X, written as Lit(X), is X U x \ x € X}, and the set 

of rules built from X, written as Rul(X) = 2^^ x ) x Lit(X), be the set of pairs of 
a set of literals built from X and a literal built from X, written as {l i, . . . , l n } — > l. 
We also write l\ A . . . A l n — > l and when n = 0 we write T —* l. Moreover, for 
x £ X we write ~a; for ->x and for x. 

- the set of effects E C Rul(X) is a set of rules built from X. 

- the motivational description MD : M —* Rul{ X) is a complete function from the 
sets of desires and goals to the set of rules built from X. For a set of motivations 
S C M, we write MD(S) = { MD{s ) | s £ S'}. 

We now extend the multiagent system to a normative multiagent system to take 
norm generation into account. To describe the normative system, we introduce a set of 
norms ( N ) and a norm description that associates violations with variables (V). 

Definition 3 (NMAS). A normative multiagent system NMAS is a tuple 

{A, A, D, G, AD , E, MD,>,N, V) 

where MAS = (A, A, D , G, AD, E, MD, >) is our multiagent system, and moreover: 

- the norms N is a set disjoint from A, X, D, and G. 

- the norm description V : N x A — > P is a complete function that maps each pair 
of a norm and an agent to the parameters, where V (n, a) represents the parameter 
that counts as a violation by agent a of the norm n. 

We define sanction and reward-based obligations in the normative multiagent sys- 
tem using an extension of Anderson’s well-known reduction [2], like Meyer [24] also 
does: violations and sanctions are the consequences of not fulfilling a norm. It covers 
a kind of ought-to-do and a kind of ought-to-be obligations. Moreover, we can also 
have that x is obligatory for agent a while it is a decision variable of another agent b. 
The logic of obligations, sanctions and rewards satisfies only replacements by logical 
equivalents. 

Definition 4 (Obligation). Let NMAS = ( A,X,D,G,AD,E,MD,>,N,V ). We 
say that: 

- x is obligatory for agent a in NMAS ijf^n £ N with — > V(n, a) £ E, 

- s is a sanction for agent a in NMAS ijf^n £ N with V (n, a) — > s £ E, and 

- r is a reward for agent a in NMAS ijf3n £ N with -<V (n, a) — > r £ E. 

The obligation for x is called ought-to-do when x £ Lit{ X \ P) and it is called ought- 
to-be when x £ Lit(P). 

This is clearly a very weak notion of obligation, and more sophisticated notions 
within this kind of framework are developed elsewhere [5]. In this paper we now turn 
to the representation of the desires and goals. 
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4 Logic of Rules 

We use a simplified version of the input/output logics introduced in [21,22]. A rule 
base is a set of rules, i.e., a set of ordered pairs p — > q. For each such pair, the body 
p is thought of as an input, representing some condition or situation, and the head q is 
thought of as an output, representing what the norm tells us to be desirable, obligatory 
or whatever in that situation. We use input/output logics since they do not necessarily 
satisfy the identity rule. Makinson and van der Torre write (p. q) to distinguish in- 
put/output rules from conditionals defined in other logics, to emphasize the property 
that input/output logic does not necessarily obey the identity rule. In this paper we do 
not follow this convention. 

In this paper, input and output are respectively a set of literals and a literal. We use 
a simplified version of input/output logics, since it keeps the formal exposition simple 
and it is sufficient for our purposes here. In Makinson and van der Torre’s input/output 
logics, the input and output can be arbitrary propositional formulas, not just sets of 
literals and literal as we do here. Consequently, in input/output logic there are additional 
rules for conjunction of outputs and for weakening outputs. 

Definition 5 (Input/output logic [21]). Let a rule base B be a set of rules 

{Pi - Qi,---iPn — > q n }> read as ‘if input p\ then output q\’, etc., and consider 

the following proof rules, strengthening of the input (SI), disjunction of the input (OR), 
and cumulative transitivity ( CT) defined as follows: 

p p A q —> r,p A ^q -> r CR P~>q,pRq->r 

p A q — » r p — > r p — > r 

The following four output operators are defined as closure operators on the set B using 
the rules above: 

out\: SI (simple-minded output) outs: SI+CT (simple-minded reus, output) 
out 2-' SI+OR (basic output) out 4: SI+OR+CT (basic reusable output) 

We write out(B) for any of these output operations and B p — > q iff p — > q £ 

out(B), and we write B hj 0 ; B' iff B hj 0 j p — > q for all p — * > q £ B' . 

The following definition of the so-called input-output and output constraints checks 
whether the derived conditional goals are consistent with the input. 

Definition 6 (Constraints [22]). Let B be a set of rules, and C a set of literals. B 
is consistent with C, written as cons{B \ C), iff there do not exist two contradictory 
literals p and -<p in C U {l \ B h io i C — > /}. We write cons(B) for cons{B \ 0 ). 

Due to space limitations we have to be brief on technical details with respect to 
input/output logics, see [21, 22] for their semantics, further details on their proof theory, 
the extension with the identity rule, alternative constraints, and examples. 

5 Joint Goal Generation by Merging Agent Desires 

We characterize the goal generation process as a merger or fusion of the desires of 
the agents, which may be seen as a particular kind of social choice process [19]. In 
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this paper, we use the merging operators for merging desires into goals in the context 
of beliefs, defined in [15]. We adapt these operators in two ways. First we simplify 
the operators, because we do not use beliefs. Secondly, and most importantly, we make 
them more complex, because we extend the operators defined on propositional formulas 
to merge rules. 

Definition 7. A rule base B is a set of rules, a rule set S is a multi-set of rule bases. 
Two rule sets S\ and £>2 are equivalent, noted S\ <-> S 2 , iff there exists a bijection f 
from S\ = {Bf . . . , B ”} to S 2 = { B . . . , BIf } such that out(f(B)) = out(B). We 
write S for the union of all rules in S, and U for union with multi-sets. 

Most of these postulates are generalizations of belief revision postulates [1, 16, 18], 
(RO) states that the result of merging complies with the integrity constraints. (Rl) en- 
sures that, when the integrity constraints are consistent we always manage to extract a 
coherent piece of information from the knowledge set. (R2) says that, if possible, the 
result of the merging is simply the conjunction of the knowledge bases of the knowl- 
edge set with the integrity constraints, (R3) is the principle of irrelevance of syntax. The 
purely ‘merging’ postulates are (R4), (R5) and (R6). (R4) is what is called the fairness 
postulate. It ensures that when merging two knowledge bases, the operator cannot give 
full preference to one of them. (R5) and (R6) correspond to Pareto’s conditions in so- 
cial choice theory [3] and were proposed in [26] to model fitting operators. Finally (R7) 
and (R8) state conditions on the conjunction of integrity constraints and make sure that 
‘closeness’ is well-behaved [18]. See the above mentioned papers for further details 
and motivations. In the following definition, as well as in all following definitions, we 
assume that a logic of rules has been fixed. 

Definition 8. Let h i a i be an output operation, S be a rule set, E a rule base, and V 
an operator that assigns to each rule set S and rule base E a rule base V E (S). V is a 
rule merging operator if and only if it satisfies the following properties: 

RO If not cons(E), then V e{S) E 
Rl If cons(E), then cons(\7 e(S)) 

R2a Sh iol \7 E (S) 

R2b Ifcons{ S U E), then V e(S) h m S 

R3 If Si <-► S 2 and Ei <-> E 2 , then V El (Si) <-> Ve 2 (S 2 ) 

R4 If B \- iol E, B' \- iol E, and cons(y e ({B} U {B'})UBUF), 
then cons{S/ e({B} U {£?'}) U B' U E) 

R5 \7 e (Si) U V e (S 2 ) L iol V E (S 1 U S 2 ) 

R6 If cons(V E (Si) U V e (S 2 ) U E), then V E (Si U S 2 ) F io , V B (Si) U V E (S 2 ) 

R7 If cons(Ei U E 2 ), then V El (£>) h lo i V Ei ue 2 (S) 

R8 If cons(V El (S) UFiU E 2 ), then V Ei ue 2 (S) h io i Vs^S 1 ) 

Additional properties can be accepted [19], but due to space limitations we do not 
discuss them. For the same reason we do not discuss the semantics of merging operators. 
The merging operator is illustrated in the following example. 

Example 1. Let I -j 0 j be out^, and consider four rule bases each consisting of a single 
rule S = {{T — > p},{ T — > q},{p — > r},{q — > -r}}. Now cons( E) does not 
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hold, so due to R 1 we cannot have V 0 (.S') = S. They can be merged into a maximal 
subset of these rules, for example we may have V0(S I ) = {T — > p, T — * q,p — > r} 
or V0 (jS i ) = {T — > q,p — > r, q — > ->r}. Note that the latter merger selects a maximal 
consistent subset of S, but it does not select a set of rules that maximizes the output 
{x | V0(5 I ) b ioi T — > a;} (a distinction discussed in [ 22 ]). If we assume b ^ be outi, 
then cons( E ), and due to R 1 we have Xq>(S) = S. 

In our conceptual model, goals are a subset of the merger of desires of the agents. 

Definition 9 (Goal generation). There is a rule merging operator V such that 
MD(G) C \/ e (MD(D x ) I x £ A). 

In the latter definition we use variable x to refer to agents. We use variables also in 
many other places, e.g., in the following example, but these variables are just used to 
shorten the presentation and are not part of the logical language. It is just some syntactic 
sugar. For example, quantification over rules means that it is schema: there is a set of 
rules, one for each agent involved. Since the set of agents A is finite, we are still in 
propositional logic. Joint goal generation is illustrated by the following example. 

Example 2 . Let NMAS = (A, X, D, G, AD, E, MD,>, N,V) with the following 
ingredients: 

variables in X : 

{-•collision(xi, X2), accident, drive jright{x), driveJeft(x ) \ xi,X2,x £ A}. 

Moreover, each agent can decide to drive on left or right side of street, e.g., 
X a = {drive jright(a) , drive Jeft(a)}, 

effect rules E: 

{drive_right(xi) I\ drive Jeft{x2) — > collision(x 1,0:2) | X\,X2 £ A} 

U {( X2 eA ~'collision{x\, X2)) — > -> accident } 

U {collision(xi, X2) — > accident \ Xi,X2 £ A } 

U {collision(xi, X2) — > collision^ X2,x\) | £1,2:2 £ A} 

If two agents do not drive on same side then they collide, and if there are no colli- 
sions then there is no accident 

desires: D x = {T — > -1 collision(x , y) \ y £ A } for each agent x £ A. Agents desire 
not to be part of a collision, 
goal G = {T — > -1 accident}. 

The system generates a joint goal of NMAS for absence of accidents. 

Goals can be generated using negotiation processes. Alternatively, the process can 
be facilitated by an agent playing the role of legislator. Here we do not further consider 
the construction of goals. 

6 Norm Creation 

We formalize norm creation as a planning problem, distinguishing between the creation 
of the obligation and the creation of the associated sanctions and rewards. In some cases 
sanctions must be associated with the norms to ensure that some agent fulfills the norm, 
and therefore to ensure that the other agents accept the norm, but in some other cases 
this is not necessary. Here are two prototypical examples. 



A: The Social Delegation Cycle 



37 



- Agents do not want to crash into each other, and the norm to drive on the right side 
of the road (or the left side, for that matter) is accepted by all members. In this case, 
no sanction is necessary and the norm may be called a convention. Other examples 
of this kind can be found in coordination games in game theory. 

- Agents want to cooperate in a prisoner’s dilemma, so the norm to cooperate is 
accepted by all members. In this case, a sanction must be associated with the norm, 
because otherwise the agent will defect (as game theory shows). 

The two elements of norm creation are formalized as two sequential steps: first de- 
termining the obligation, and thereafter determining the associated sanctions or rewards. 
The first step is essentially a planning problem: the obligations of the agents must im- 
ply the joint goal Y — > g. We represent a norm n by an obligation for all agents in the 
multiagent system, that is, for every agent a we introduce an obligation ~x — > V(n,a). 
Moreover, since goals can only be in force in a context, e.g., Y, we introduce in context 
Y an obligation FA — > V (n. a). Roughly, the condition is that all obligations x 
imply the goal g. 

However, to determine whether the obligations imply the goal, we have to take the 
existing normative system into account. We assume that the normative system only 
creates obligations that can be fulfilled together with the already existing obligations. 
Moreover, for the test that the goal g will be achieved, we propose the following con- 
dition: if every agent fulfills its newly introduced obligation, and it fulfills all its other 
obligations, then g is achieved. We define a global violation constant V as the disjunc- 
tion of all indexed violation constants like V(n , a), i.e., V = nGN aGA V(n, a). 

Definition 10 (Norm creation). Let NMAS = (A, X , D, G , AD, E, MD, >, N, V) 
with Y — > g £ MD(G). The parameters contain the global violation constant V £ P 
and E contains the following set of rules: 

{V(n, a) — ► Y | n £ N, a £ A} U {-iV — > ->V ( n,a ) | n £ N, a € A} 

The creation of norm n' to achieve joint goal Y — > g leads to the updated normative 
multiagent system (A, X, D, G, AD, E U E' , MD,>, N U {n 1 }, V) such that: 

1. The norm n! is not already part of N ; 

2. A set of rules E' = { Y Ax — > V ( n ' , a) \ a G A, x € Lit(X)} is a set of obligations 
for each a € A such that E U E' hj 0 j A Y — > g, if all norms are fulfilled, then 
the joint goal is satisfied; 

3. cons(E | Y A — 'V), it is possible that no norm is violated. 

The creation of norms is illustrated by the following example. 

Example 3. Let NMAS = (A, X, D, G, AD, E, MD, >, N, V) as defined in Exam- 
ple 2. Assume that the normative system creates a norm n' with the following obliga- 
tions: Va £ A : -i right_side(a ) — > V (n 1 , a): ~^right_side(a) counts as a violation of 
norm n' by agent a. 

The second step is adding sanctions and rewards. The condition of this second step 
is that sanctions are disliked, and rewards are desired. 

Definition 11 (Norm creation with sanctions and rewards). Let NMAS =bea nor- 
mative multiagent system ( A , X, D, G, AD, E, MD, >, N, V) with Y — > g € MD{G). 
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The creation of norm n' with sanctions and rewards to achieve joint goal Y — > g leads 
to the updated system {A, X, D, G, AD, E U E' U E" , MD,>,NU {if}, V) with: 

1. The creation of norm n' to achieve joint goal Y — > g leads to updated system 
(A, X, D, G, AD, E U E' , MD, >,NU {n'}, V) and 

2. The set of rules E" = {Y A V{n',a) — > s \ a £ A, s £ Lit{X)} U 
{Y A -i V(n',a) — > r \ a £ A,r £ Lit{X)} is a set of sanctions and rewards 
for each a £ A such that for all such s and r we have D a bj a i Y — > -is or 
D \~ioi Y — > r: sanctions are undesired and rewards are desired. 

Sanctions are illustrated by the following example. 

Example 4. Let NMAS = ( A, X, D,G, AD, E, MD,>, N,V ) with the following 
ingredients: 

agents A: {a, &}; 
variables in X : 

{c(a), c(b) , cooperation, s(a),s(b)} with X a = {c(a)}, X b = {c(b)}, each agent 
can cooperate (e.g., c(a )) or not, each agent can be sanctioned (e.g., s(a)) or not. 

effect rules E: 

{c(a) A c(b) — > cooperation} , there is cooperation if both agents cooperate, 
desires D: D a = {T — > ->c(a),T — >■ cooperation, T — > -is(a)}, 

Df, = {T — > -<c(b),T — > cooperation, T — > ->s(&)}. 

Agents desire to defect (e.g., ->c(a)), but they also desire cooperation, and they 
desire not to be sanctioned. 

goal G = {T — > cooperation} , the system has generated a joint goal of NMAS for 
cooperation. 

Assume that the normative system creates a norm n' with the following obligations: 
E' = {->c(a) — > V {n’ , a) \ a £ A}: ->c(a) counts as a violation of norm n' by agent a. 
Moreover, it adds the following sanctions: E" = {V(n’ , a) — > s(a ) | a £ A}. 

There may be a third step that adds controls to the obligations, sanctions and rewards. 
We do not consider this extension in this paper. 

7 Norm Acceptance 

An agent accepts a norm when the obligation implies the desires the cycle started with, 
and moreover, it believes that the other agents will fulfill their obligations. We propose 
the following games: agent a plays a game with arbitrary agent b and accepts the norm 
if agent b fulfills the norm given that all other agents fulfill the norm , and this fulfil- 
ment leads to fulfillment of its personal desire the cycle started with. This implies that 
fulfillment of the goal g is kind of normative equilibrium. 

Definition 12 (Decision). Let NMAS = ( A,X,D,G,AD,E,MD,>,N,V ). The 
optimal decision of agent b £ A given a set of literals C is defined as follows. 

- The set of decisions is the set of subsets of Lit(Xf) that do not contain a variable 
and its negation. A decision S is complete if it contains, for each variable in X b, 
either this variable or its negation. 
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- The unfulfilled desires of decision S for agent b £ A are the desires whose body is 
part of the decision, but whose head is not. 

U{5 , b) = {d £ D b | MD(d ) = L — > l, E bj 0 ; CU(5-> l' for V £ L and E \fi 0 \ 
CU<J -> /}. 

- A decision S is optimal for agent b if and only if there is no decision S' such that 
U{S,b) > b U(S', b). 

We use the definition of optimal decision to define the acceptance relation. We de- 
fine a variant V^t, of the global violation constant Y as the disjunction of the violation 
constants of all agents except agent b. We assume here that the agents only consider 
typical cases. In reality there are always exceptions to the norm, but we do not take this 
into account. 

Definition 13 (Acceptance). Let NMAS = (A,X,D,G,AD,E,MD,>,N,V), 
and let NMAS' = (A, X, D, G, AD, £U£'U E" , MD, >,N U {n'}, V) be the 
system after the creation of a norm and its associated sanctions and rewards. The pa- 
rameters contain the global violation constants Y^ b £ P and E contains the following 
rules: 

{V(n, x ) — > Y ^,b | n £ N,x £ ^4 \ {£>}} U — > ->Y(n, a) \ n £ N,x £ A\ {fe}} 

An agent a £ A accepts the norm if: 

1. There is a desire in D which is not satisfied in NMAS, but it is satisfied in 
NMAS'. 

2. For all other agents b £ A, we have that the optimal decision of agent b assuming 

implies ->X. 

Norms do not always need to be accepted in order to be fulfilled, since the sanction 
provides a motivation to the agents. However, for a norm to be really effective must be 
respected due to its acceptance, and not only due to fear of sanctions. 

It can easily be shown that in the two running examples, both norms are accepted. 

8 Further Research 

8.1 Trust 

For more realistic but also more complex social trust, we have to enrich the model with 
beliefs. We have to extend the merging operators to merging in the context of beliefs, 
see [15]. Consequently, we have to introduce beliefs in norm creation, and we have to 
make the acceptance relation relative to beliefs. 

8.2 The Creation of Permissive Norms 

It is not directly clear how the social delegation cycle can explain the creation of per- 
missive norms. One way to proceed is to define permissions as exceptions within hier- 
archical normative systems [12]. 

8.3 Social Institutions and the Creation of Constitutive Norms 

How to take social institutions into account in the social delegation cycle? Based on 
Searle’s construction of social reality, we may introduce besides the obligations or reg- 
ulative norms also constitutive norms, which are definitions of the normative system 
based on a counts-as conditional [9]. 
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9 Related Work 

9.1 Other Work 

The relation between ‘desires’ or internal motivations and ‘obligations’ or external mo- 
tivations has been studied in many areas, for example: 

Religion. The Golden Rule or the ethic of reciprocity is found in the scriptures of 
nearly every religion. It is often regarded as the most concise and general principle 
of ethics. It is a condensation in one principle of all longer lists of ordinances such 
as the Decalogue. 

Ethics. Kant’s categorical imperative [17] expresses the moral law as ultimately en- 
acted by reason and demanding obedience from mere respect for reason. 

Political theory. Marx (ideology) [23]: the ruling class forms a theory (obligations) 
justifying itself (its desires). 

Social theory. Norms (obligations) are only accepted if the legislator does not make 
them only for his own interests (desires) ([14]). 

Agent theory. Your wish is my command: the desires of the master are the obligations 
of the slave. 

Within formal and semi-formal agent theory, there has been some work by Castel- 
franchi, Conte and colleagues on norm adoption and norm acceptance [14]. 

9.2 Normative System as an Agent 

In other work we discuss applications of normative multiagent systems [5], of which 
the formal machinery based on rule based systems and input/output logics has been de- 
veloped in various papers. In those papers the agents consider the normative system as 
an agent, and they attribute mental attitudes to it, because the agents are playing games 
with the normative system to determine whether to fulfill or violate norms. We refer to 
this use of the agent metaphor as “your wish is my command”: the goals of the norma- 
tive agent are the obligations of the normal agents. In the present paper, however, the 
agents play games with other agents, and the attribution of mental attitudes to normative 
system is not a necessary assumption. In our other work, we have informally discussed 
the notion of the social delegation cycle in a short paper [4]. In that short paper we have 
suggested that the social delegation cycle can be used to explain the agent metaphor 
“your wish is my command”, because the group goal from which the norm is created, 
may be interpreted as the goal of the normative system, and the normative system is 
doing a kind of planning. 

In this framework, we have not discussed the merging of desires into group goals, 
but we have mentioned the notion of rational norm creation in a second short paper [7], 
In that paper we do not present a formalization of norm creation, and we do not consider 
norm creation within the context of the social delegation cycle. Finally, we introduce 
an extension of our formal model with constitutive norms in [9] and we observe that 
constitutive norms play an important role in norm creation, but we do not formally 
study it. The creation of permissions in this framework has been mentioned in [6]. 

Finally, in none of our other work we have discussed the acceptance relation, and 
we have not discussed games between ordinary agents. 
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10 Summary 

In this paper we consider the relation between desires and obligations in normative mul- 
tiagent systems. We introduce a model of their relation based on what we call the social 
delegation cycle, which explains the creation of norms from agent desires in three steps. 
First individual agent desires generate group goals, then a group goal is individualized 
in a social norm, and finally the norm is accepted by the agents when it leads to the 
fulfillment of their initial desires. The social delegation cycle may be seen as a gener- 
alization of single agent decision making, which can also be defined as a combination 
of goal generation and planning. Additional issues in the social delegation cycle are the 
role of sanctions and rewards, the acceptance relation, and the implicit assumption of 
fairness in goal generation. Moreover, in the social delegation cycle institutions may 
play a role. 

We formalize the social delegation cycle combining theories developed in a general- 
ization of belief revision called merging operators, planning and game theory. First, we 
formalize joint goal generation as a merging process of the individual agent desires, for 
which we extend existing merging operators to deal with rules. Second, we formalize 
norm creation as a planning process for both the obligation and the associated sanctions 
or rewards. Third, we formalize the acceptance relation as both a belief of agents that 
the norm leads to achievement of their desires, and the belief that other agents will act 
according to the norm, introducing a notion of normative equilibrium which states that 
agents fulfill norms when other agents do so. 

There are two main directions for further research. First, the theories have to be ex- 
tended with beliefs and institutions to cover social delegation cycles based on trust and 
norm creation by institutions. Second, for the social delegation cycle efficient mecha- 
nisms should be designed which can be employed in actual implementations of norma- 
tive multiagent systems. Desirable properties may be soundness (compliance with our 
framework), completeness (for each possible goal there is a goal generated), concise- 
ness of goals and norms generated, generality of goals and norms generated, strictness 
of goal generation and norm creation, et cetera. 
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Abstract. This paper studies the logic of a dyadic modal operator for 
being obliged to meet a condition p before a condition <5 becomes true. 
Starting from basic intuitions we arrive at a simple semantics for dead- 
line obligations in terms of branching time models. We show that this 
notion of deadline obligation can be characterized in the branching time 
logic CTL. The defined operator obeys intuitive logic properties, like 
monotony w.r.t. p and anti-monotony w.r.t. <5, and avoids some counter- 
intuitive properties like agglomeration w.r.t p and ‘weak agglomeration’ 
w.r.t. S. However, obligations of this type are implied by the actual 
achievement of p before the deadline. We argue that this problem is 
caused by the fact that we model the obligation only from the point of 
view of its violation conditions. We show that the property might be 
eliminated by considering success conditions also. 



1 Introduction 

This paper studies the logic of a dyadic modal operator, denoted 0{p < J), for 
being obliged to meet a condition p before a condition 5 becomes true. To satisfy 
the obligation, it suffices to satisfy the condition p only once, at a time of ones 
choosing, as long as it is before (or, ultimately, at) the point where the condition 
5 occurs. We refer to the operator 0{p < S) as a ‘deontic deadline’ operator. We 
do not claim that all deadlines have a deontic aspect. For instance, in the field of 
‘scheduling’ [1], deadlines are hard constraints that have to be satisfied under all 
circumstances. However, in more realistic situations, where agents may choose 
to violate deadlines imposed on them by other agents, it is much harder to deny 
the deontic aspect 1 . 

Conceptually, deontic deadlines are interactions between two dimensions: a 
deontic (normative) dimension and a temporal dimension. So, to study deadlines, 
it makes sense to take a standard temporal logic, say CTL [2-4] , and a standard 
deontic logic, say SDL [5], and combine the two in one system. This type of 
approach is for instance taken in [6]. The problem then is how to account for 
the interactions. Conceptually, we have to keep in mind that in the combined 
system we can express that the normative content of the deontic operators can 

1 If deadlines are not due to commitments towards other agents, but the result of per- 
sonal decisions based on personal desires, it is more adequate to talk about ‘deadline 
intentions’. 
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be temporal (e.g, being obliged to be polite always), but also that obligations can 
have some (non-) dynamical behavior over time (e.g., always being obliged to be 
polite). It is easy to mix up these essentially different propositions. The same kind 
of confusion threatens the study of deadlines. Is a deadline (1) an obligation at a 
certain point in time to achieve something before another point in time, or (2) is 
a deadline simply an obligation that persists in time until a deadline is reached, 
or (3) is it both? In natural language it is actually quite hard to be precise about 
this distinction. Therefore, for now, we rely on in informal understanding of the 
branching time temporal logic CTL, and the standard deontic logic SDL, to 
discuss the distinction using formulas. In CTL, the symbols E and A denote an 
existential and a universal quantifier respectively, ranging over possible future 
courses (branches) of time. Within the scope of these quantifiers, CTL uses the 
linear time operators (LTL [3]) ipUif (strong Until, i.e., if) will occur, and ip holds 
up until then), ipU w il> (weak Until, i.e., if if will occur, then ip holds up until 
then) to talk about individual future courses of time (from now on simply called 
‘possible futures’). From SDL we use the operator O, for obligation. 

In a language that combines CTL and SDL we can talk about both the tem- 
poral and deontic dimensions independently. For instance, we can talk about a 
certain obligation being preserved over time: A{OpU w <5) , which says ‘the obliga- 
tion to achieve p persists until S, and if 6 does not occur, it persists forever’. Or 
we can talk about the obligation that a certain condition p has to be achieved 
before a condition S occurs: 0(->E(->pUS)). This says ‘it is obliged that on no 
possible future p is avoided until <5 becomes true’ (alternatively we may read this 
as ‘it is forbidden that on some possible future p is avoided up until <5 becomes 
true’). 

However, in this paper we do not use a language where we can talk about both 
dimensions independently. We see the deontic dimension as ‘embedded’ in the 
temporal dimension 2 , the only difference being that it is considered exclusively 
with certain violation [7] and ideality [8] constants that hold or do not hold at 
certain points in time. 

The advantage of this approach is that we study deadlines entirely in CTL 
supplemented with violation 3 and ideality constants. The disadvantage is that 
the language is not expressive enough to talk about the deontic and temporal 
dimensions independently. In particular, we cannot talk about the dynamics of 
obligations. So, a background assumption of our study will be that agents do 
not get new obligations, or are explicitly discharged of some of their obligations, 
when time evolves. In yet other words: there are no explicit ‘deontic updates’. 
This implies that if in a next state the deadline 8 or the achievement p is not 
realized, the deadline obligation persists. In sections 4 and 5, we present formulas 
that correspond to this background assumption for two different version of the 
deadline operator. 



2 Technically this corresponds with the deontic accessibility relation being enclosed 
by the temporal accessibility relation. 

3 The idea of expressing the semantics of deontic deadlines by characterizing violation 
conditions in CTL supplemented with violation constants [7] , was first explored in [9] . 
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We model the deadlines themselves as propositions. This seems a reasonable 
choice given that we do not want to model a deadline in a logic of explicit time 
(real time). Our view is more abstract, and a deadline is simply a condition S 
true at some point in time. A consequence of this abstract view is that we have 
to deal with the possibility that S actually never occurs. Note that for a theory 
of deadlines that uses an explicit notion of time, this would never be a problem. 
In particular, the point ‘two hours from now’ will always occur, while meeting 
a condition ‘S’ may be impossible or extremely unlikely. However, our abstract 
view contributes to the relevance of the present research for other logical systems. 
For instance, Rao and Georgeff’s commitment strategies [10] are actually a sort 
of deadlines: an agent commits to an intention until the action is performed or 
believed not to be feasible any longer. 

The choice in this paper for the temporal logic CTL is a pragmatic one. We 
believe the theory applies equally well, and maybe better, to linear time temporal 
logic (LTL [3]). However, CTL has nice properties (P-complete complexity of the 
model checking problem for CTL, versus PSPACE-complete complexity for LTL 
[11]), and is popular in agent theory [12]. 

2 Preliminaries: CTL 

A well-formed formula p of the temporal language EqTL is defined by: 

p,ip,... := p | ->p | p A ip | E(pU ee ip) | A(pU ee ip) 

where p, ip represent arbitrary well-formed formulas, and where the p are ele- 
ments from an infinite set of propositional symbols V . We use the superscript 
‘ee’ to denote that this is the version of the ‘until’ where p is not required to 
hold for the present, nor for the point where ip, i.e., the present and the point 
where </> are both excluded. This gives us the following informal meanings of the 
until operators: 

E{pU ee ip) : there is a future for which eventually, at some point in, the condi- 
tion ip will hold, while p holds from the next moment until the 
moment before m 

A{pU ee ip) : for all futures, eventually, at some point m, the condition ip will 
hold, while p holds from the next moment until the moment 
before m 

We define all other CTL-operators as abbreviations 4 . Although we do not use 
all of the LTL operators X , F, and G in this paper, we give their abbreviations 

4 Often, the CTL-operators EGp and E(ipUp) are taken as the basic ones, and other 
operators are defined in terms of them. The advantage of that approach is that we 
do not have to use the notion of ‘full path’, that is crucial for the truth condition of 
A(pU ee ip). However, that approach is not applicable here, since we cannot define the 
‘exclusive’ versions of the operators in terms of them. And, even if we take EGp and 
E(ipU ee p) as basic, we can still not define the for our purposes important operator 
A(ipU e p) as an abbreviation. 
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(in combination with the path quantifiers E and A) in terms of the defined op- 
erators for the sake of completeness. We also assume the standard propositional 
abbreviations. 



EXp = def E(±U ee p) 

EFp = def p V E{TU ee p) 
AFp = def p V A(TU ee p) 
A{pU e ip) =def P A A(pU ee ip) 
A{pUip) = def A(pU e (p A VO) 
A(pU w 1p) = de f ->E{-i%j}U-dp) 



AXp = de f -iEX-iip 
AGp = de f -‘EF-'ip 
EGp = de f -iAF-iip 
E(pU e ip) = def p A E(pU ee ip) 
E(pUip) = de f E(pU e (p A VO) 
E{pU w iP) = de f -^A(-tipU^p) 



The informal meanings of the formulas with a universal path quantifier are as 
follows (the informal meanings for the versions with an existential path quantifier 
follow trivially): 



A(pU e ip) 

A(pU VO 

A(pU w ip) 

AXtp 

AFtp 

AGtp 



for all futures, eventually, at some point to, the condition ip will 
hold, while tp holds from now until the moment before to 
for all futures, eventually, at some point the condition ip will hold, 
while tp holds from now until then 

for all possible futures, if eventually ip will hold, then p holds from 

now until then, or forever otherwise 

at any next moment p will hold 

for all futures, eventually p will hold 

for all possible futures p holds globally 



A CTL model M = (S,lZ,n), consists of a non-empty set S of states, an 
accessibility relation 1Z, and an interpretation function 7 r for propositional atoms. 
A full path a in M is a sequence a = So, s ii s 2 , • • • such that for every i > 0, 
Si is an element of S and SilZsj+i, and if a is finite with s n its final situation, 
then there is no situation s n + 1 in S such that s n lZs n +i. We say that the full 
path a starts at s if and only if s 0 = s. We denote the state s* of a full path 
cr = so, Si, S 2 , . . . in A4 by cq. Validity A4, s (= p, of a CTL-formula p in a world 
s of a model M = ( S , 1Z , 7r) is defined as: 



M,s 


\= 


p 






S <E 


7r(p) 


M,s 


1= 


~np 






not 


M,s |= p 


M,s 


H 


p A ip 






M, 


s |= p and A4 , s |= ip 


M,s 


h 


E(pU ee ip) 




3(7 


in A4 with a 0 = s, and 3 n > 0 such that: 












(1) 


A i,cr n | = ip and 












(2) 


Mi with 0 < i < n it holds that A 4, \= p 


M,s 


1= 


A{pU ee ip) 




V(T 


in A4 such that uq = A it holds that 3n>0 such that 



(1) M, a n |= ip and 

(2) Vi with 0 < i < n it holds that M, |= p 



Validity on a CTL model A4 is defined as validity in all states of the model. If 
p is valid on a CTL model A4 , we say that A4 is a model for p. General validity 
of a formula p is defined as validity on all CTL models. The logic CTL is the 
set of all general validities of tL over the class of CTL models. 
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3 A Dyadic Deontic Deadline Operator 

We minimally extend the language C(jy l by extending the set of propositional 
atoms with a violation constant of the form Viol 5 . Furthermore, the formal in- 
terpretation of the atom Viol is treated like that of all other atomic propositions. 
So, we can view the propositional constant Viol also as a special element of V: 
a ‘special purpose’ proposition solely used to interpret deontic formulas in a 
temporal dimension. 

Let M be a CTL model, s a state, and a a full path starting at s. A straight- 
forward modal semantics for the operator O v ( p < 5), where the V is only a 
label to emphasize that this operator is defined in terms of Violations, is then 
defined as follows: 

M., s |= O v {p < (5) <f=> Vcr with cr 0 = s,Vj : 
if 

M,<Jj |= S and VO < i < j : M , cq |= ->p 
then 

A i,<Jj \= Viol 

This says: if at some future point the deadline occurs, and until then the 
result has not yet been achieved, then we have a violation at that point. This 
semantic definition is equivalent to the following definition as a reduction to 
CTL: 

O'" ( p < 6) =def —'E(—<pU(5 A —Viol)) 

This formula simply ‘negates’ the situation that should be excluded when a 
deontic deadline is in force 6 . In natural language this negative situation is: l S 
becomes true at a certain point, the achievement has not been met until then, 
and there is no violation at S\ Therefore this CTL formula exactly characterizes 
the truth condition for the above defined deontic deadline operator: the semantic 
conditions are true is some state if and only if the the CTL formula is true in 
that state. 

4 Logical Properties 

What logical properties of the operator O v (p < S) does this bring us? We first 
discus the property that corresponds to out background assumption that there 
are no deontic updates. It holds that: 

|= O v (p <6)-> A(O v (p < S)U w p) 

To see that this holds 7 , it is easiest to fall back on the semantics of the 
operator. The semantics says that on futures (branches of time) where S occurs 

5 For reasoning in a multi-agent context we may provide violation constants of the 
form Viol (a) where a £ A, and A an infinite set of agent identifiers. 

6 Alternatively this definition can be given using the weak until: O v (p < <5) =def 
A((-i<5 V Viol)U w p). But for the version with the strong until it is much easier to see 
that it corresponds with the semantic truth conditions defined above. 

7 Alternatively we may write this as |= 0(p < 6) — » -'E(-‘pU-’0(p < 5)). But in our 
opinion, here the version with the weak until is easier to understand. 
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at some point t, while until then p has not been done once, there is a violation 
at t. Now, if we follow such a branch for some time-steps in the future, and we 
do not meet a p, then, the deadline conditions do still apply: still it holds that 
if <5 will occur later on, we get a violation if we do not meet a p until then. 
An important observation is that even if we have passed one or more (5-states, 
the obligation still applies; only if we meet a p, the conditions are no longer 
guaranteed. Thus, the defined notion of deadline persists, even if we have passed 
a deadline. This might be considered counter-intuitive, since it seems correct to 
assume that the deadline obligation itself is discharged by passing the deadline. 
Therefore, in section 5 we show how to define a version that does not have this 
property. However, we consider the present notion of deadline not as counter- 
intuitive, but merely as a variant. Persistence of the obligation at the passing of 
a deadline is not a priori counter-intuitive. An example is the following: you are 
obliged to repair the roof of your house before it will rain (or otherwise you and 
your interior get wet). This obligation is only discarded by the act of repairing 
the roof, and not by the event of raining. 

We now turn to other properties of the operator of section 3. First of all we 
get monotonicity with respect to p (other terminology: validity of the operator 
is closed under weakening of p) 8 . Monotonicity says that we have as validities 9 : 

\=O v ((pA X )<6)^O v (p<6) 

|= O v (p<S)^O v ((pV X )<S ) 

This is in accordance with intuition: if p is made logically weaker, it is easier 
to satisfy. So, if the stronger condition has to be accomplished before S occurs, 
then certainly also the weaker condition has to be accomplished before S occurs. 

A property we do not have is agglomeration with respect to p, i.e.: 

¥= O v (p <S) A O v (x <S)^ O v {{p A x) < (5) 

This shows that O v (p < (5), is monotonic with respect to p, but is not 
a normal modal operator with respect to p. This means that it is a strictly 
monotonic modal operator with respect to p. Exactly this same logic behavior 
is known from intentions [13]: an intention for p and an intention for q do not 
necessarily give an intention for p A q, because we may intend p for another 
point in the future then the point for which we intend q. That the behavior of 
deadline obligations is similar to that of future directed intentions is not unlikely, 
given the intuition that intentions can be seen as a kind of obligations to oneself. 
A consequence of the absence of agglomeration is that it is consistent to have 

8 In section 6 we will see a simple way to prove weakening and strengthening for the 
defined operators. However, all other verifications are left to the reader. 

9 To express the property we call ‘monotonicity’ it suffices to give just one of these the- 
orems, because they can be derived from each other using only the rules of uniform 
substitution and substitution by logical equivalents. However, to check the intuitive- 
ness of monotony, especially for deontic operators, it is wise to consider both these 
‘appearances’ of monotony. 
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O v (p < 5) A O v (-<p < 6). Consistency of obligations of the form Op and 0~>p 
is heavily debated in deontic logic. Here we have consistency simply because we 
are free to choose our time of compliance, as long as it is before the deadline. 

Also we get that the operator is anti-monotonic with respect to 6 (other 
terminology: validity of the operator is closed under strengthening of (5): 

\=O v {p<5)^O v {p<{5A 1 )) 

b O v {p<{5\I^))^O v {p<5) 

For this version of the operator, this is in accordance with intuition: if 5 
is made logically stronger, it is harder to satisfy. And if p already has to be 
accomplished before the weaker condition occurs, it will certainly have to be 
accomplished before the stronger condition occurs. This property does not go 
through for the version of the deadline we discuss in section 5. As said, in that 
variant, the obligation is discharged by the first condition (5 we meet. Then, by 
strengthening 6, it is not necessarily the case that we preserve the obligation. 

A property we do not have for O' ( p < 6) is ‘weak agglomeration’ with 
respect to p, i.e.: 

b O v {p <S) A O v (p < 7) -4 O v {p < {8 V 7)) 

This means that the deontic deadline operator O v (p < 5 ), is strictly anti- 
monotonic with respect to 5. If it would also obey weak agglomeration, it would 
have been a window operator [14,15], which means that it would have been 
a normal modal operator with respect to ~<5 [16,17]. However, the operator is 
strictly anti-monotonic. This is intuitive. Weak agglomeration should not hold, 
because having to achieve something before tomorrow and having to achieve the 
same thing before the end of the day does not imply that I have the choice to 
do it before tomorrow or before the end of the day: it simply gives me no other 
choice than to do it before the end of the day. 

The combination of monotony for p and anti-monotony for 6 gives us the 
following transitivity property for the deontic deadline operator O v (p < 6) 10 : 

b O v {p <S) A O v (S < 7) -4 O v (p < 7 ) 

Also this property is intuitive: if an agent is obliged to brush his teeth before 
going to bed, and take a medicine before he brushes his teeth, then he is certainly 
obliged to take has medicine before going to bed. 

Clearly, the deadline operator should not be symmetric. Indeed we have: 

b O v (p<S)^O v (S<p) 

Another property we do obey is reflexivity: 

b ° v (i < 7) 

Taking advantage of the definability in CTL, it can be shown that we actually obey 
a stronger version of this property: |= O v (p < 8) A AG(8 — » x) A O v (x < 7) — » 

O v (p < 7) 



10 
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This is exactly the reason why we use the symbol “<’ and not the symbol 
in the denotation for the operator. If we achieve the obliged condition at the point 
of the deadline, we are still in time. In particular, if the deadline condition itself 
coincides with the condition we are obliged to achieve, whatever this condition 
is, we are always ‘just in time’ to meet the deadline. However, some would say 
that it is counter-intuitive to actually always be obliged to achieve any 7 up and 
until 7. 

We might argue that the situation is comparable to the axiom O T of standard 
deontic logic. The common denominator of these properties is that they concern 
an obligation for something that actually can never be violated. The point is 
that although it seems strange that our logic validates obligations for things 
that cannot be violated, it is not harmful either. No agent will ever let his 
decision making be influenced by obligations for things that are true inevitably 
and always. In other words, such obligations are void. However, we will see in 
section 7 a solution to a related, but more serious problem will discard this 
property, which means that we no longer have to defend it by saying that it is 
counter-intuitive but harmless. 

Let us now consider the related issue of having a tautology or contradiction 
as deadline, or as a condition to achieve. We first consider the case where p 
equals T. We have that: 

(= O v (J < 6) 

This is related to the monotony with respect to p ; we can weaken p up until it 
coincides with T. This situation is similar to standard deontic logic’s O T, which 
we already discussed. 

Just like we can weaken p up until T, we can strengthen 8 up until _L (from 
the anti-monotony with respect to d). 

\=O v (p<±) 

Clearly, _L is a condition that will be never met. So, an obligation to perform 
something before the (absent) point that T, can never be violated. We can 
postpone the obligation forever, without ever falling pray to a violation. In our 
view, such obligations are void. Therefore, also this case is similar to standard 
deontic logic’s O T. 

Another issues is the case where p equals 1 or d equals T. These conditions 
deserve extra attention. First we discuss the case where p equals _L. This concerns 
the question whether something general holds for obligations for conditions that 
under no circumstance can be achieved. One view is that obligations of the form 
0(J_ < 8) are impossible or inconsistent. After all, it seems reasonable to take 
the position that one can never be obliged to achieve the impossible. This view 
would demand that we validate ->O v {l. < 8 ), which is similar to standard deontic 
logic’s D-axiom ->0 _L. However, it is clear that we do not validate “1 O v (J_ < 
d). In our semantics, this would mean that we validate EF{8 A ~<Viol ), which 
directly contradicts our intuitions: it is not the case that any condition 8 will be 
met eventually. But this does not answer the question whether we should obey 
-1 O v (J_ < 8). We belief we should not. Note first that our setting is weaker than 
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that of standard deontic logic. In particular, since we do not have agglomeration, 
we can satisfy O l (p < S) A O v (~>p < 6). This simply says that before 5, we have 
to satisfy p at some point, and we have to satisfy at some point. That this 
cannot be the same point does not exclude the conjunction. However, this does 
not yet explain why it is not excluded that we satisfy O v (_L < S). This is because 
this is no ordinary obligation but a deadline obligation. As we already discussed, 
we can have that the deadline itself is a condition that can never occur. And we 
argued that for that situation, the obligation is trivially met. But then we can 
also satisfy the formula O v (_L < <5) by choosing _L for <5. We get O v (_L < _L), 
which is not only satisfiable, but also valid. So, obligations of the form O v (_L < S) 
are not inconsistent; in particular they can be met if 5 never occurs. Intuitively: 
an agent can consistently meet up to the obligation to do something impossible 
before S just in case that < 5 will never occur. Analogously, we can discuss the case 
where S equals T. Now the agent is obliged to achieve p now. In our semantics 
this is possible. Therefore O v (p < T) is satisfiable. Similar to the above case, 
we may even choose p to be T to get the valid formula O' (T < T), which says: 
an agent is obliged to obey a tautology now. 

However, from the above discussion, it follows that there is a deadline obli- 
gation that really should be inconsistent: O v (A. < T): agents cannot achieve 
the impossible now, since, by definition, the present state is not an impossibility. 
And indeed, we have the following property: 

h -O y (T < T) 

5 A Variant without Strengthening 
of the Deadline Condition 

The deadlines as discussed in section 3 are not discarded by meeting the deadline: 
as long as the condition p is not yet achieved, we have a violation at every 
point where the deadline condition 5 holds. In other words: the obligation is 
not discarded by having failed a deadline. Here we drop this property. Thus the 
obligation is dropped the first time we meet the deadline condition, irrespective 
of whether we have achieved the goal or not. In the definition of section 3, we 
need to add that only the first S occurring, is relevant. 

M , s \= 0' v {p < <5) <t=> Vct with ao = s, \/j : 
if 

M. , <jj |= —i/o A A and VO < i < j : M., cr, |= ->p A ->5 
then 

A |= Viol 

This says: if at some future point the deadline occurs for the first time, and 
until then the result has not yet been achieved, then we have a violation at 
that point. For this notion of deadline it is a slightly harder to give a CTL 
characterization. We need to use the notion of until that talks about the states 
until the last state before ip (i.e., ipU e p). 

0' v {p < S) =def — , E((—<p A —<5)U e (5 A —<p A —>Viol)) 
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The main point of this variant is thus that it has a different dynamical 
behavior. In particular, it is discarded by the first 8, even if the achievement has 
not been met. Therefore, the following preservation property holds: 

h °' V (p < s )^ A (0' v (p < S)U w (p V (5)) 

For this variant all logical properties of the variant of section 3 hold, except 
strengthening. Thus: 

V=O lV {p<5)^O lV {p<{5 A 7 )) 
V=0' v {p<{5\/ 1 ))^0' v {p<5) 

It is clear that the following holds for the relation between the two variants: 
H O v {p <8)^ 0' v {p < 8) 



6 A Counter-Intuitive Logical Property 

The operators defined in sections 3 and 5 obey intuitive properties. However, 
there is a property, or more precise, a class of properties, which are satisfied by it, 
but whose intuitiveness is disputable. These possibly counter-intuitive properties 
are caused by the definition of a deadline from the viewpoint of its violation 
conditions only. The idea behind the definitions was ‘give an exact temporal 
characterization of the conditions under which the deadline is violated ’. This 
idea is correct as long as we are interested in the temporal conditions implied 
by a deontic deadline. But what about the temporal conditions that give rise 
to a deontic deadline? It turns out that here something might be missing. For 
instance, we have the following property (From now on we will only consider the 
first version of the operator. The discussion for the other version is analogous.): 

\=P^O v (p<8) 

It says that the deadline obligation of section 3 is implied by the actual 
achievement of p in the current state. Moreover, this property is only an instance 
of a more general, stronger property that holds for the deontic deadline operator 
of section 3. The obligation is valid in any state where it is sure that the deadline 
will be met. In particular: 



h ~-E(^pU8) O v ( P < (5) 

This can be verified by substituting the CTL characterization of the deadline 
obligation: -i E(->pUS) ->E(-<pU(8 A -Viol)). We may see this as the strength- 

ening of 8 to 8 A -Viol in the schema ~^E{-^pU8). It is quite easy to see that 
this strengthening property holds. We start with the fact that validity of the the 
schema E(ipUip) is closed under weakening with respect to p and with respect 
to ip, that is, if at some point in a model we satisfy E(ipUif>), we also satisfy both 
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E((ip\/ rfUip) and E(ipU(ip\/"/)). But this means 11 that the schema ~>E(ipUip) is 
closed under strengthening with respect to ip, which is what we needed to show 
(with —ip substituted for ip, and <5 for ip). 

Now the question rises whether we cannot defend intuitiveness of this prop- 
erty in the same way as we defended intuitiveness of, for instance |= O v (7 < 7) 
and 1= O v (T < 8) and \= O' (p < _L). We might argue that if p is unavoidable, 
in particular, if it is true now, then the deadline O' ( p < 8) is void, because it 
concerns an achievement that is met anyway. 

However, we consider the issue whether or not p — > O' ( p < 8) to be different 
from, for instance, the issue whether or not O' (T < 8). Whereas the second 
obligation is void because the obligation concerns a tautology, i.e., something 
that is considered to be true inevitably and always, the first obligation results 
from a condition that can be considered to be only occasionally true. Therefore, 
we would like to have a mechanism that enables us to avoid this property while 
retaining the good properties. 

7 A Solution 

We argue that this problem is caused by the fact that we model the obligation 
only from the point of view of its violation conditions. We show that the unde- 
sired property is eliminated by considering success conditions also. The solution 
we arrive at, preserves the good properties. First we investigate how we can define 
a deadline operator O s {p < 8) using success conditions (propositional ‘ideality’ 
constants) only. We show that if we look at the operator from this more positive 
angle, we arrive at similar logical properties. However, also this approach has 
a (quite obvious) counter-intuitive consequence. We show that to eliminate all 
counter-intuitive properties we may combine both failure and success conditions. 

We extend the language £cTL with an ideality constant [8] Idl. Let M be 
a CTL model, s a state, and a a full path starting at s. We can now define a 
success condition based semantics for a deontic deadline operator O s (p < 8), 
where the S stands for Success, as follows: 

M,s\= O s (p < 8) oVa with op = s, V) : 
if 

M, a j |= 6 

then 

30 < i < j : M., (Ti f= p A Idl 

This says: for all possible futures it holds that if at some point the deadline 
occurs, then until then, there has at least been one ideal state where p has been 
achieved. Note that it would not be correct to define that all p-states before S 

11 We actually use some background theory here about how logical properties of defined 
operators can be determined by looking at the way they are constructed from simpler 
operators. In particular, a negation in the definition flips closure under strengthening 
to closure under weakening and vice versa. This is why any modal operator Mp is 
closed under weakening (strengthening) if and only if its dual -<M-np is closed under 
weakening (strengthening) . 
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are ideal; if a p is met, the obligation is discharged, and no ideal states should 
occur anymore 12 . 

The above semantic definition is equivalent to the following definition as a 
reduction to CTL: 



0 S (p < <5) —def A Idl)US) 

Note that due to its form, this definition also obeys all the logical proper- 
ties discussed in section 4. To be more precise, also the operator O s (p < S) is 
a monotonic operator with respect to p (i.e. , closed under weakening with re- 
spect to p), and an anti-monotonic operator with respect to S (i.e., closed under 
strengthening with respect to <5). And, in addition, it does not obey the counter- 
intuitive p —> O s (p < S), because now it requires the presence of an ideal state 
to have an obligation of the form O s {p < <5). To be more precise, we have that: 

-<E(^pU5) ~^O s {p< 5) 

This follows, because, as we argued in section 4, the construct -> E(-<pUS), 
is not closed under agglomeration with respect to p, which implies that it is 
certainly not anti-monotonic (closed under strengthening) with respect to p. So 
p cannot be strengthened to p A I dl while preserving truth. 

However, obviously, also with this operator something is wrong. We have 
that: 

|= O s (p < (5) — > —>E(—ipU S) 

That is, deadline obligations O s (p < 5) cannot be violated; success is guar- 
anteed. Before giving the remedy, let us first explain why the above prop- 
erty is valid for the success based deadline definition. Valididty of the schema 
-iE(-i(pAldl)US) is closed under weakening with respect to pAldl , so weakening 
p A Idl to p, does not destroy truth. 

Now how can we combine the intuitions from the present section with the 
ones of the previous sections, to arrive at a deadline operator that excludes 
all counterintuitive properties? We will not give the semantic truth-conditions 
of this final operator we define, and leave it to a characterization as a CTL 
formula (the semantic truth-conditions can easily be obtained by combining the 
conditions for the earlier defined operators): 

0(p < S) =def —'E(—>(p A Idl)U(S A —i Viol )) 

First of all, it is clear that this operator preserves the good properties. Due to 
its form we have monotonicity with respect to p, anti-monotonicity with respect 
to S , etc. But we also avoid the counter-intuitive property ~^E(^pU5) 0{p < 

S), because we have strengthened p to pAldl. And we avoid the counter-intuitive 
0(p < 5) — > -• E(-ipUS), because we have strengthened <5 to 5 A -> Viol (which 

12 This actually implies that an ideal state can only be the first p-state encountered 
before the deadline <5. The consequences of introducing this stronger condition will 
be investigated on another occasion. 




Designing a Deontic Logic of Deadlines 



55 



means that S is weaker than S A Viol). Informally, the formula says that there 
is a deadline obligation only if there is a violation if the achievement is not met 
at the deadline, or there is success if the achievement is accomplished before the 
deadline. 

A positive side-effect of this operator is that we now have that [A 0(7 < 7 ) 
and 0 ( T < S). So, some of the properties we considered to be intuitively 
unattractive, but harmless, are no longer valid. But, we do still have that |= 
0(p < -L). 

8 Discussion and Conclusion 

Given that obligation concerns action, that action involves change, and that 
change presupposes time, deontic and temporal aspects have very strong con- 
ceptual connections. Therefore, any contribution to the study of such connections 
is welcome. 

In this paper we discussed intuitions concerning the notion of ‘being obliged 
to obey a condition p before a condition 5 occurs’. We made a simplifying as- 
sumption that enabled us to study this notion in the logic CTL, minimally ex- 
tended with violation constants. We defined two dyadic modal operators for the 
mentioned notion, and showed that they obey several intuitive logical properties. 
Finally, to prevent the operators from obeying some counter-intuitive property 
also, we proposed to consider success conditions. 

It would be interesting to test the logic by means of a CTL-tlreorem prover. 
There are no such implemented theorem provers available. However, they can be 
written by using the results in either [18] or [19]. We plan to do this in the near 
future. 

There are many directions for future research. For instance, we want to in- 
vestigate whether the semantics also applies to other temporal formalisms (in 
particular LTL). Another point concerns abandoning the background assump- 
tion that there are no deontic updates. How much of the theory can be preserved 
if we do allow updates? Also we want to study the notion of permission in this 
setting (a simple definition is P(p < S) =def < 6)). 

Finally we note that the combination of failure and success conditions was 
used before in deontic formalisms [20]. However, to our knowledge, the idea to 
evaluate failure and success conditions at different points in time for defining 
the semantics of a deontic concept, is new. 

We thank Leendert van der Torre, Joris Hulstijn, Melrdi Dastani and Henry 
Prakken for lively and illuminating discussions on this subject. We thank the 
anonymous referees for valuable suggestions and references. 
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Abstract. Obligation change raises the “frame problem” which is to 
characterise what obligations remain unchanged after an action has been 
performed. Many general solutions have been proposed but even if they 
are attractive from a thoretical point of view they have practical draw- 
backs. 

In this paper simple solutions are proposed thanks to the restriction 
to obligations that take the form of modal literals. These solutions are 
presented in the framework of dependence logic and of situation calculus, 
and it is shown that they are based on the same intuitive idea. This 
idea is to express that we have a complete representation of actions and 
circumstances that can change an obligation. 



1 Introduction 

The problem of the characterisation of what remains to be true after the per- 
formance of an action is recognised as a difficult problem in the field of Articial 
Intelligence. This problem is usually called the “frame problem”. 

The same problem arises in the field of deontic logic if we want to characterise 
the set of obligations that persist after an action. It has some connections with 
deontic defeasibility but it is not the same problem (see [10, 1, 12, 9, 17]). 

An interesting solution to the frame problem has been proposed by Reiter [11] 
in the framework of situation calculus for modelling the evolution of the world. 
Later on this solution has been extended to the evolution of beliefs about the 
world by Sclrerl and Levesque [16, 14]. This work has been extended to revision 
by Shapiro et al. in [15]. In [4] Demolombe has adapted their intuitive ideas 
to the evolution of obligations. However, this solution has practical drawbacks 
because it requires to assign to all the ideal situations an ideality level in the 
same way as Scherl and Levesque require the assignement of a plausibility level. 

In this paper we investigate solutions to the frame problem which are less gen- 
eral, in the sense that we only consider facts that can be represented by literals, 
but are simpler to formalise and much easier to use for practical applications. 
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The first idea is to consider the dependence logic, which has been defined by 
Castilho, Herzig et al. in [2, 3] (section 2) and to extend it to obligations (section 
3). The second idea is to extend the simple idea of successor state axioms in 
situation calculus to obligations about literals (section 4). At the end of the 
paper the two formalisations are compared and it is shown that they are based 
on the same intuitive ideas (section 5). 

2 Dependence Logic 

The dependence logic is a propositional modal logic with the two modal operators 
□ and [a]. Sentences of the form D(p) are read: p is true after any sequence of 
actions, and sentences of the form [a] (p) are read: p is true after the action a. 

For modelling an application domain the effects of the actions are defined by 
properties of the form: 

□(9 — > VAp) 

For instance, in the typical example of the Yale Shooting Scenario we have: 
□ {Loaded — » [shoot]-* Alive) 

This intuitively means that after any sequence of actions, if the gun is loaded 
then after shooting the man is not alive. 

In addition to the definition of the action effects we have a set of frame 
axioms of the form: 

□ (-•C —>■(£—>■ [a}L)) 

where L is a literal and C is a formula of classical propositional logic. 

In a metalanguage this axiom says that if we are not in the context C the 
truth value of L is independent of the action a. That is, there is a ternary 
relation between a, L and C, and the frame axioms could be represented in the 
metalanguage by this independence relation. 

The problem is that for almost every applications the set of frame axioms 
is very large, because after an action most of the literals have the same truth 
value. 

Then, it is easier to represent the dependence relation, which is the comple- 
ment of the independence relation, than the independence relation itself. Let us 
call D the dependence relation, we suppose that D is finite. The fact that the 
tuple (a, P, C) is in D means that in the context C the truth value of the atom 
P may be changed by the action a. It is assumed that the dependence relation 
is complete in the sense that a may change the truth value of P only if there 
is a tuple (a, P, C) in D. 

The logic which is based on this dependence relation is called LAPD 1 . It is 
formally defined as follows. 

ATM is the set of atomic formulas of the language. We have ATM = 
{P, Q , . . .}. LIT is the set of literals. ACT is the set of actions. We have ACT = 
{a, (3 , . . .}. PFOR denotes the set of formulas of classical propositional logic. 

The dependence relation is such that D C ACT x ATM x PFOR. 

1 LAPD abreviates Logic for Action and Plan with Dependence relation. 
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Semantics 

A model for the logic LAPD is a structure /i such that: 
p=<W,{R a : a € ACT}, R a ,T >. 

In /r: 

— W is a set of possible worlds, 

— Ra and R a are two accessibility relations which interpret □ and [a], 

— r is a function from ATM to 2 W ; t is extended as usual to the logical 
connectives. 

The following constraints are imposed on /i: 

— Ra is reflexive and transitive, 

Ra Ra , 

— if wR a w' then 

VP G ATM if VC G PFOR((a, P,C) G D => w ^ C) then 
w G t(P) iff w' G t(P). 

The intuition of the last constraint is that if all the contexts C where a may 
influence P are false in w, then P has the same truth value in w and w' . 

We adopt the notation: 

Pre D (a, P) = \J C 

{ a,P,C)eD 

It is assumed that Prev{a, P) = T if there is no tuple in D of the form: 
(a, P, C). 

Let us denote by \L\ the atom of the literal L. We have the property: 

| =lapd □(-> Prei )( a , |P|) -A (L ^ [a]L)) 

From the relation D we obtain the formula Previa, |L|), and from this prop- 
erty we have the corresponding frame axioms. 

For instance, if Prev{a, P) = C we have the frame axioms: 

\=lapd □(“'C — > (P — > [a]P)) 

\=LAPD □(-’C -A (-1 P [a]->P)) 



Axiomatics 

The axiomatics of the LAPD logic is defined as follows: 

— all the tautologies of the classical propositional logic, 

— [a] obeys the schema K, 

— □ obey the schemas K, T and 4, 

— (/) Up -a [a\p, 

— ( Persist ) -> Prev{a , \L\) — > (L — > [a]L), 

— Modus Ponens and Necessitation for □ and [a]. 

It has been proved (see in the Annex) that this axiomatics is valid and 
complete. 
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Example 

We can see now how this logic can be applied to the Yale Shooting Scenario. 
The dependence relation D is D = {dl, d2, d3}, where we have: 

(dl) (load, Loaded , T) 

(d2) (shoot, Loaded, T) 

(d3) (shoot, Alive, T) 

The set of effect laws is LAW = {1,2, 3, 4}, where we have: 

(1) 0[load]Loaded 

(2) U[shoot\~^ Loaded 

(3) □ (Loaded -A [shoot]^ Alive) 

(4) D(-^Loaded A Alive -A \shoot\Alive) 

Let us assume that the current situation is represented by KB = {-• Loaded , 
Alive}. 

Since there is no tuple in D of the form (load, Alive, C) we have Preo(load, 
\Alive\) = Y. Then, from the schema ( Persist ) we have the frame axiom: 

(5) Alive — > [load]Alive 
From (5) and KB we have: 

(6) [load\Alive 

From (1) and (T) we have: 

(7) [load]Loaded 

From the schema (I) and (3) we have: 

(8) [load](Loaded -A [shoot\-> Alive) 

And from (7) and (8) we have: 

(9) [load\[shoot\~^ Alive 
From (4) and (T) we also have: 

(10) -i Loaded A Alive — > [shoot] Alive 
Then, from KB we have: 

(11) [shoot\Alive 

If we apply the Necessitation rule to the frame axiom (5) we have: 

(12) [shoot](Alive — > [load]Alive) 

From (11) and (12) we have: 

(13) [shoot][load\Alive 
Finally we have: 

\~lapd KB A LAW -A [load][shoot]^ Alive 
I - lapd KB A LAW -a [shoot][load]Alive 

It is interesting to see how the property Alive persists after the actions shoot 
and load. 

3 Extension of Dependence Logic to Obligations 

In the previous section we have seen how dependence logic provides us with a 
simple solution to the frame problem. This simplicity comes from the fact that 
the evolution of the world is described in terms of evolution of classical literals. 
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Here this approach is extended to the evolution of obligations, where this 
evolution is described in terms of modal literals. 

We introduce the new modality Obg and sentences of the form Obg{p) are 
read: it is obligatory that p. The new dependence logic extended to obligations 
is called LAPDO. 

A modal literal has the form: Obg(P), ^Obg(P), Obg(^P) or ~^Obg(^P), 
where P £ ATM. The set of modal literals is denoted by LITM. 

If LM £ LITM we denote by \LM\ the classical atom in LAI. For instance, 
we have \Obg{->P)\ = P. 

To characterise the modal literals whose truth values may change after an 
action we define the dependence relation DO such that DO C ACT x ATAI x 
PFOR. 

The fact that a tuple (cc, P, C) is in DO means that if C holds the action a 
may change the truth value of Obg(P), -> Obg(P ), Obg(~>P) or -i Obg(->P ). 



Semantics 

A model of the logic LAPDO is a structure p such that: 
g=(W,{R a : a £ ACT},R a ,Rob g ,T). 

In p: 

— W, R a , R a and r are defined like in LAPD 2 . 

— Robg is an accessibility relation which interprets Obg and is reflexive. 

The following constraints are imposed to p: 

— R a C R a and Robg C R a , 

— if wR a w' then 

VP £ ATM if VC e PFOR((a, P,C) £ D => w ^ C) then 
w £ t(P) iff w' £ r(P). 

— if wR a w' then 

VP £ ATM if VC e PFOR((a, P,C) £ DO => w ^ C) then 
w £ r(Obg(P)) iff w' £ r(Obg(P)) and 
w £ T(Obg(~>P)) iff w' £ r(Obg(-<P )). 

The last constraint on LAPDO models means that if we are not in a context 
where the action a may change the truth values of the modal literals formed 
with P, then their truth values remain unchanged after a. 

The constraint Robg C R a requires some comments. Indeed, a consequence 
of this constraint is that we have (= D(p) — > Obg(p). Then, for example, from 
□ (Loaded — ► [shoot]->Alive) we can infer Obg(Loaded — > [shoot]~> Alive). This 
consequence may seem to be odd in a first approach. 

In fact this is acceptable if the intuitive meaning of Obg{p) is: p is true in 
all the ideal worlds, and if we accept that ideal worlds are a subset of the “real 
worlds” . Here we call real world a world which satisfies all the properties that are 

2 The function r is extended to obligations in a natural way. We have r(Obg(p )) = 
{ w : w \= Obg(p)}, and w \= Obg(p) iff wRob g w' implies w' \= p. 
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necessarily true in a given application domain. In particular all the properties 
that define the effects of the actions must hold in a real world. 

Why should we impose that the ideal worlds are a subset of the real worlds? 
Suppose, on the contrary, that there is an ideal world w which is not a real world. 
That means that in w there is a property of the domain which is not satisfied. 

Let us consider, for example, the property: a person cannot be at two different 
places at the same time. Then, in w it could be the case that the same person is 
at two different places at the same time, and, from a normative point of view, it 
would be permitted for a person to be at two different places at the same time. 
It would be very odd to define a regulation with such a permission. That is why 
it is imposed that ideal worlds are real worlds. 

We adopt the notation: 

Pre DO (a,P)= \J C 

{ a,P,G)eDO 

If LM £ LITM we have the property: 

| =lapdo □ ( _, -Pre£>o(<A \LM\) — > ( LM — > [a]LM)) 

For example, if Preooiot, P) = C we have: 

1 =lapdo n ( _, C -A (Obg(P) -A [a]Obg(P))) 

\=lapdo n( _, C -A (-1 Obg(P) -A [a\~<Obg(P))) 

\=lapdo n ( _, C -A (Obg(—iP) -A [a\Obg(-iP))) 

\=lapdo n( _, C — > (-i Obg(~>P ) -* [a\^Obg(->P))) 

Axiomatics 

The axiomatics of the LAPDO logic is defined as follows: 

— all the tautologies of the classical propositional logic, 

— [a] obeys the schema K, 

— □ obeys the schemas K, T and 4, 

— Obg obeys the schemas K and D, 

— (/) Up -a [ a\p , 

— (O) Up -A Obg(p), 

— ( Persist ) -^Prejj(a, \L\) -A (L -A [ce]L), if L £ LIT , 

— ( Persisto ) - Pre DO {a , \LM\) -A ( LM -A [ a\LM ), if LM £ LITM, 

— Modus Ponens and Necessitation for □, [a] and Obg. 

It has been proved that this logic is valid and complete (see in the Annex). 



Example 

Let us take the example of the traffic lights to show how obligation change is 
formalised in LAPDO. We use the following notations 3 : 

3 As a matter of simplification we have ignored the case where the light is orange. 
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Red', the light is red. 

Green : the light is green. 

InCrossing : the car is crossing the crossroads. 

For the actions we use the notations: 

red : to switch the light to red. 
green : to switch the light to green. 
start. cr : to start to cross the crossroads. 
end.cr: to end to cross the crossroads. 

The relation D is D = {dl, d2, d3, dA , d5, d6} where: 

(dl) (red, Red, T) 

(d2) (red, Green, T) 

(d3) (green, Red, T) 

(d4) (green, Green, T) 

(d5) (start. cr, InCrossing, T) 

(d6) ( end.cr , InCrossing, T) 

The relation DO is DO = {dol,do2} where; 

(dol) (red, InCrossing, T) 

(do2) (green, InCrossing, T) 

Note that start. cr and end.cr have no influence on obligations. 

The set of effects laws is LAW = {71, 12, 13, 14, 15, 16, 17} where: 

(11) □[redJJSed 

(12) D[green]Green 

(13) 0[start.cr\InCrossing 

(14) n(end.cr\-^InCrossing 

(15) E)[red]Obg(^InCrossing) 

(16) a[green]Perm(InCrossing) 

(17) D-i(Red A Green) 

As usual Perm(p) is an abreviation for -i Obg(—<p). The current situation is 
represented by KB = {^InCrossing, Green, Perm(InCrossing)}. 

From (11) and (T) we have: 

(1) [red]Red 
From (Persist) we have: 

-> InCrossing — > [red]^InCrossing 
Then, from KB we have: 

(2) [red]^InCrossing 
From (15) and (T) we have: 

(3) [ red]Obg(^InCrossing ) 

Therefore from (1), (2) and (3) we have: 

\~lapdo LAW A I\B -A [ red](Red A ^ InCrossing A Obg(^InCrossing)) 

It is worth noting that (Persisto) does not allow to infer: 



Perm(InCrossing) -A [red]Perm(InCrossing) 
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because we have the tuple (red, InCrossing, T) in DO. Then the permission 
Perm.(InCrossing) does not persist after the action red. 

From (Persist) we have: 

Red -4 [start. cr\Red 
By Necessitation we have: 

[red\(Red — > [start.cr\Red) 

And from (1) we have: 

(4) [red\[start.cr\Red 
From (13) and (I) we have: 

(5) [red][start.cr]InCrossing 
From ( Persisto ) we have: 

Obg(-^InCrossing) — > [start. cr]Obg(-^InCrossing) 

And by Necessitation we have: 

(red](Obg(-^InCrossing) — > [start. cr\Obg(-^InCrossing)) 

Then, from (3) we have: 

(6) [red] [start. cr\Obg(^InCrossing) 

Therefore from (4), (5) and (6) we have 

\~lapdo LAW A KB -A- [red\[start.cr] 

(Red A InCrossing A Obg(~^InCrossing )) 

It can be shown in a similar way that we have: 

Llapdo LAW A KB — > [red][green\[start.cr\ 

( Green A InCrossing A Perm(InCrossing)) 

This example shows how the obligations about the fact InCrossing are up- 
dated when the actions red and green are performed. 

4 A Simple Extension of Situation Calculus 
to Obligation Change 

The situation calculus is a typed first order classical logic (except some limited 
fragments that are in the second order). The characteristic feature of this logic 
is that dynamic aspects are represented by the notion of situation, which can be 
quantified, and each predicate whose truth value may change when actions are 
performed has an argument of the type situation. These predicates are called 
fluents. 

For instance, the fact that the light is red in the situation s is represented by 
Red(s). A situation may be the initial situation So, or the situation obtained after 
performance of the action a from the situation s. This situation is represented 
by the term do(a, s). 

For example, the situation do(start.cr, So) represents the situation where the 
car has crossed the crossroads, and do(red, do(start.cr , So)) represents the situa- 
tion where the light has switched to red after the car has crossed the crossroads. 

To solve the frame problem in a given application domain we have to define 
for each fluent the complete list of the actions and circumstances that cause the 
fluent to be true or that cause the fluent to be false. 
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For example, the action red causes the light to be red and the action green 
causes the light not to be red. This is formally represented by: 

(51) VsVa(a = red — > Red(do(a , s))) 

(52) VsVa(a = green — > ~^Red(do(a, s))) 

To represent the fact that there are no other action that cause Red or ->Red 
we have to add the properties: 

(Cl) VsVa(-ii?ed(s) A Red(do(a , s)) — > a = red) 

(C 2) \/s\/a(Red(s) A ~>Red(do(a, s)) — > a = green ) 

It can be shown that (SI), (S2), (Cl) and (C2) are logically equivalent to 

(SSI). 

(551) \/s\/a(Red(do(a, s)) -O- a = red V Red(s) A ^(a = green)) 

In the same way we have: 

(552) \/s\/a(Green(do(a, s)) O a = green V Green(s) A ->(a = red)) 

(553) \/s\/a(InCrossing(do(a, s)) O a = start. cr V InCrossing(s) A ->(a = 
end.cr)) 

Notice that from (SSI) and (SS2) it can be easily proved by induction that 
-i(Green(5o) A Red(So)) — > \/s(^(Green(s) A Red(s))). 

If we assume that each action has a unique name, from (SSI) we have: 

\/s(Red(do(start.cr, s)) •o- Red(s)) 

Its intuitive meaning is that the action start. cr does not change the fact that 
the color of the light is red. In other terms the status of Red persists after any 
action other than red and green. That gives a very simple solution to the frame 
problem. 

In general, for each fluent we have to define a successor state axiom of the 
form: 

\/s\/a(p(do(a, s)) -O- T + (a, s) V p(s) A -i r~(a, s)) 

To avoid inconsistencies we have to impose the constraint: 

-■3s3a(T + (a, s) A r~(a, s)) 

The solution to the frame problem is based on two key ideas: we define the 
evolution of the world by defining the evolution of each literal, and we assume 
that we have a complete knowledge of the causes of their evolution. The same 
ideas will be applied to the evolution of the obligations in the same way as 
Demolombe and Pozos did for the evolution of beliefs [6] . 

In a first step we define obligations in the same way as Scherl and Levesque 
have defined beliefs in the situation calculus. 

We adopt the definition: 

Obg(p,s) = f Vs , (0(s , ,s) -»p[s']) 

where the arguments of the type situation have been removed in p, and they 
have been replaced by s' in p[s']. 0(s',s) is a classical predicate that plays the 
same role as an accessibility relation. 

To define the successor state axioms for obligations the only difference is that 
modal literals correspond to four truth values, while classical literals correspond 
to two truth values. 
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For example, to define the evolution of the four modal literals formed with 
the atom InCrossing we have the properties: 

(OS'!) VsVa(_L — > Obg(InCrossing, do(a, s))) 

(05 2) VsVa(a = red —> -> Obg(InCrossing , do(a, s))) 

(05 3) VsVa(a = red —> Obg(-^InCrossing , do(a , s))) 

(054) VsVa(a = green — >• ~^Obg(^InCrossing, do(a , s))) 

And we have four properties to represent the fact that the causes of change are 
complete: 

(OC 1) \/s\/a(~iObg(InCrossing, s) A Obg(InCrossing , do(a, s)) — > _L) 

(OC 2) \/sVa(Obg(InCrossing, s ) A ->Obg(InCrossing, do(a, s)) — > a = red) 
(OC 3) \/sVa(^Obg(^InCrossing, s ) A Obg(-^InCrossing , do(a, s)) — » a = red) 
(OC 4) \/s\/ci(Obg(^InCrossing(s))A^Obg(^InCrossing, do(a, s)) — >■ a = green) 

It can be shown that (OSl)-(OS4) and (OCl)-(OC4) are logically equivalent to 
(OSS1) and (OSS2). 

(OSS 1) \/s\/a(Obg(InCrossing , do(a , s)) -O- Obg(InCrossing , s) A -i(a = red)) 
(OSS 2) \/s\/a(Obg(^InCrossing, do(a, s)) -O- a = red V Obg(~^InCrossing , 
s) A -t(a = green)) 

Let us consider an initial situation defined by A'i? = { ^InCrossing(So ), 
Green(So ) , Perm(InCrossing, S'o)}. 

From (SSI) we have: 

(1) Red(do(red, So)) 

From (SS3) and KB we have: 

(2) ~^InCrossing(do(red, So)) 

From (OSS2) we have: 

(3) Obg(^InCrossing, do(red, So)) 

If we denote by AS the set of properties AS = {551, 552, 553, 0551, 

0552} we have: 

b AS A KB Red(do(red, So)) A ~<InCrossing(do(red, So)) A Obg(->InCro 
ssing, do(red, So)) 

Notice that in So it is permitted to cross the crossroads while in do(red, So) it 
is forbidden to cross. This shows that the action red requires obligation updating. 
We can also notice that the fact -> InCrossing persists after the action red. 
From (SSI) and (1) we also have: 

(4) Red(do([red, stai't.cr], So)) 4 
From (SS3) we have: 

(5) InCrossing(do([red , start.cr ], 5o)) 

From (0SS2) and (3) we have: 

(6) Obg(^InCrossing, do([red, start.cr ], 5o)) 

Therefore we have: 

b AS A KB — > Red(do([red 1 start.cr ], 5o)) A InCrossing(do([red , start.cr ], 
5o)) A Obg(^InCrossing,do([red, start.cr], So)) 

4 do([red, start.cr], So) is an abreviation for do(start.cr, do(red, So))- 
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It can be shown in a similar way that we have: 

b AS A KB — > Green(do([red, green, start.cr], So)) A InCrossing(do([red , 
green, start.cr ], So)) A Perm(InCrossing, do([red, green, start.cr ], 5b)) 

In general for each normative fluent we must define two successor state axioms 
for obligations of the form: 

\/s\/a(Obg(p, do(a, s)) -fA (a, s) V Obg(p, s ) A ~<r^ (a, s)) 

\/s\/a(Obg{-ip, do(a, s)) t-A r£ (a, s) V Obg(-^p, s) A -i/TT (a, s)) 

To guarantee the consistency of obligations we impose the constraints: 
->3s3a(r+ (a, s) A T) - (a, s)) 

->3s3a(/T)" (a, s) A T 2 _ (a, s)) 

To satisfy the schema (D) we impose the constraint: 

-i3s3a(r+ (a, s) A (a, s )) 

Moreover, from (D) we have: Obg(p, do(a, s)) —> ~^Obg(^p,do(a, s)). In addi- 
tion we have: r^(a,s) —> Obg(p,do(a,s)). Then, we can infer: r^(a,s) — >■ 
^Obg(^p, do(a, s)). Since r^(a, s)) represent all the circumstances that cause 
^Obg(^p, do(a, s)) we must impose the constraint: 

VsVa(T 1 + (a, s) -T 2 - (a, s)) 

For a similar reason we impose the constraint: 

VsVa(r 2 (a, s) — > r{~(a,s)) 



5 Comparison between Situation Calculus 
and Dependence Logic 

To analyse the links between the evolution of obligations expressed in the situ- 
ation calculus or in the dependence logic, we shall consider a translation from 
situation calculus to a dynamic logic, and from this dynamic logic to dependence 
logic. Then, it is shown that consequences derived in dynamic logic correspond 
to the consequences derived in dependence logic. 



5.1 From Situation Calculus to Dynamic Logic 

In [5] Demolombe has presented a general method to translate situation calculus 
formulas into formulas of a dynamic logic. 

As a matter of simplification we only consider here the translation of the 
successor state axioms for the obligations. 

Without loss of generality it can be assumed that the /)s have the following 
form. 

T+ (a, s) = f a = a A C+ (s) 

Tf(a,s) = f (a = /3 ACf(s)) V (a = 7 AC 2 + (s)) 

T 2 + (a, s) = f a = 7 A C} (s) 

/Tr(a, s) = f (a = ^ A C 2 ~ (s)) V (a = a A (s)) 

It is assumed that the C)s contain no symbol of the type action. 
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In r j _ we have the subformula a = 7 A C^ (s) because a = 7 A C £ (s) implies 
Obg(^p,do(a, s)), and, since obligations should obey (D), Obg(^p,do(a, s)) im- 
plies ~^Obg(p,do(a,s)). Then, a = 7 A C^(s) causes ~>Obg(p, do(a, s)). We have 
a = a A Cj 1 " (s) in T 2 _ for a similar reason. 

All the results would be the same if instead of Tj + we had: 

r+(a, s ) d = (o = ar A C+^s)) V . . . V (a = a n A C+ n (s)) 

The same comment holds for the other TjS. 

Thanks to the unique name axioms we can easily check that the Fs satisfy 
all the constraints mentioned in the previous section. 

Then, the properties that define the effects of the actions on the obligations, 
and the completion properties are: 

(Cl) VsVa(a = a A C+ (s) — ► Obg{p, do(a, s))) 

(C2) VsVa((a = f3 A Cr(s)) V (a = 7 A Ctis)) —*■ ~^Obg(p, do(a, s))) 

(C3) VsVa(a = 7 A C+(s) -»• 0& 5 (-.p, do(o, s))) 

(C4) VsVa((a = <5 A Cj~ (s))V(s = aA Cj 1 " (s)) — > ->Obg(->p, do (a, s))) 

(C5) \/s\/a(->Obg(p, s) A Obg(p, do(a, s)) —>■ a = a A C^ (s)) 

(C6) VsVa(Obg(p, s ) A ~^Obg(p, doia , s)) — » (a = (3 A Cf(s)) V (a = 7 A Co" (s))) 
(C7) VsVa(-06 5 (-p, s) A 06 fl (-.p, do(a, s)) -> a = 7 A C+(s) 

(C8) \/sVa(Obg(-ip,s)A-<Obg(-ip,do(a,s)) -A (a = MC)"(«))V(a = aAC^ (s))) 

It is worth noting that the set of formulas (C1)-(C8) is logically equivalent 
to (C9) and (CIO). 

(C9) V sWa(Obg(p, do(a, s)) tA (a = a AC)*“(s)) V Obg(p, s) A~i((a = (3 A Cf (s))V 
(« = 7AC 2 + (s)))) 

(CIO) Vs\/a(Obg(~>p, do(a, s)) O (a = 7 A C^s)) V Obg(^p,s) A ->((a = <5 A 
C 2 - (s)) V (a = a A C^ (s)))) 

The translation of these properties into dynamic logic is based on the follow- 
ing property: 

b Obg(p , do(a, s)) O Vs"(s" = do(a, s) — > Vs'(0(s / , s") — ► p[s'])) 

This property justifies the translation of Obg(p 1 do(a, s)) into [ a\Obg(p ). 

Formulas of the form VsC(s) are translated in dynamic logic into OF, where 
all the arguments of the type situation have been removed from the fluents that 
occur in F(s). 

To translate formulas of the form VaG(a) it is assumed that the quantification 
domain for the actions is the set of actions that occur in some formula to be 
translated, plus another distinct action e. 

Then, we assume that we have the following domain closure axiom for the 
actions: 

Va(a = aVa = /3Va = 7 Va = (5Va = e) 

From this axiom the translation of VaG(a) is G(a)AG(/3 )AG( 7)AG(5)AG(e), 
which is equivalent to the set of formulas: G(a), G(/3), G(y), G(6), G(e). 

Notice that it is not necessary to have several distinct actions ei , . . . , e n like 
e. Indeed, in the evaluation of the conditions of the form: e, = a, e, = /?, e, = 7 
and ej = 6, we always get the result _L for every gj. Then, every e, would lead to 
a translated formula of the same form. 
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Finally the translation of the set of properties (C1)-(C8) leads to: 

(Dl) a(C+ [a\Obg(p)) 

(D2) a(Ci ^ [PhObg(p)) 

(D2f) □ (C+ -»■ [ 7 ]- Obg{p)) 

(D 3) □(C^ ->• [i\Obg(->p)) 

(DA) □ (C' 2 “ -► [ S]-Obg(->p)) 

(DA) □ ((?+ [a]-Obg(-v)) 

(D5) n(-,Obg(p) A [a]0&p(p) -► Ct) 

(D6) D(Obg(p) A ^(/3\Obg(p) -7 Cf) 

(D6') □ (06p(p) A -{7]C%(p) -> C^) 

(D7) 0(-iObg(-ip) A MO^d-ip) — >• CA) 

(D8) 0(Obg(^p) A [$]-.0&p(-.p) -► C 2 “) 

(£>8') □ (Ofcp(-p) A [a]^Obg(^p) C+) 

Since in the situation calculus the actions are deterministic, in dynamic logic 
we must have the schema —>\a]—>p — > [a]p. Moreover, in the situation calculus 
every situation has a successor for any action. Then, we must also have the 
schema: [a]p — > —>{a]—>p. To sum it up, in the dynamic logic we must have the 
axiom schema (DD). 

( DD ) [a]p •o- -i[a]-ip 

5.2 From Dynamic Logic to Dependence Logic 

We consider a propositional dynamic logic with the axiom schema (DD). 

The effects of the actions are represented by the properties (D1-(D8’). 

From the properties (D1)-(D4’) we know that the following tuples are in the 
dependence relation for obligations DO. 

(ol) (a,p,C?) 

(°2) (/J.p.C'f) 

(°3) (7 ,P,C£) 

(°4) <5,P,C 2 ") 

From the completion properties (D5)-(D8’) we know that there is no other 
tuple in DO. Therefore we have: DO = {ol, o2, o3, o4}. 

The set of formulas in LAW is (D1)-(D4’). 

To have the same properties as in the dynamic logic we add to the dependence 
logic the axiom schema (DD). 



5.3 From Dependence Logic to Dynamic Logic 

Let us consider a dependence logic with the axiom schema (DD). 

Let us assume that in this dependence logic the effects of the actions are de- 
fined by the set of sentences in LAW, and the dependence relation for obligation 
is DO, and LAW and DO are the same as in the previous section. 

We can show that in this dependence logic obligations change in the same 
way as in the previous dynamic logic. 
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Let us denote by Mp a modal literal of the form: Obg(p ), ~<Obg(p ), Obg(->p) 
or -i Obg(—<p). From the axiom schema ( Persisto ), and from the relation DO , 
we have the following frame axioms. 

(/ 1) —'C+ — > ( Mp — » [i a]Mp ) 

(/2) -Cf (Mp \(3\Mp) 

(/ 3) -C 2 + (Mp [ 7 ]Mp) 

(/4) (Mp (5}Mp) 

We can prove that in the dependence logic from (fl)-(f4) we can infer (D5)- 
(D8’). Since (D1)-(D4’) are in the dependence logic and in the dynamic logic, in 
both logics we have (D1)-(D8’), and the evolution of obligations is the same. 

For example, we can prove that (fl) implies (D5). Indeed, if (fl) is trans- 
formed in clausal form and if we apply Necessitation for the operator □ we 
get: □(-■Mp V [a\Mp V C^). Then, for Mp = -<Obg(p) we ha ve:0(Obg(p) V 
[a\~>Obg(p) V C ( l_ ). Moreover, from the schema (DD) we have: -<[a]Obg(p) -O- 
[a\->Obg(p)\ then, we have: 0(Obg(p) V ~>[a]Obg(p) V C) 1 "), which is the clausal 
form of (D5). 

In a similar way we can prove that (f2) implies (D6). Indeed, if (f2) is trans- 
formed in clausal form and if we apply Necessitation for the operator □ we have: 
0(-iMpV[/3]Mp\/ Ci ). Then, for Mp = Obg(p) we have: 0(^Obg(p)V[/3\Obg(p)\/ 
Ci) which is the clausal form of (D6). 

6 Conclusion 

Two simple solutions to the frame problem for obligations have been presented 
in the framework of dependence logic and of situation calculus. These solutions 
are restricted to obligations that apply to classical literals, and obligations are 
given the semantics of standard deontic logic. As we can see by the traffic light 
example the solutions work for iterated obligation changes, too. 

It has been shown that both frameworks lead to the same consequences for 
obligation change. At the intuitive level the two solutions are based on the same 
ideas. A technical difference is that dependence logic requires some kind of meta 
reasoning, while situation calculus deals with classical logic but modalities have 
to be represented by a predicate that plays the role of an accessibility relation. 
The similarity between intuitive ideas can be shown as follows. 

Let us assume that the action e has no influence on the obligations about 
the atom p. That means in the dependence logic that there is no tuple of the 
form ( e,p,C ) in the dependence relation DO , and by meta reasoning we can 
infer Prepo^iP) = -L. Then, from ( Persisto ) we have the four frame axioms: 
Obg(p ) —> [' e\Obg(p ) 

->Obg(p) —> \e]->Obg(p) 

Obg(~>p) [e\Obg(~>p) 

^Obg(^p) [e\->Obg(-‘p) 

From the schema (DD) we have — i[e] — ■ (f> O [e]</>. Then the four frame axioms 
are equivalent to the two frame axioms: 

[e]Obg(p] O Obg(p) 

[e\Obg(^p) Obg(-ip) 
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In the situation calculus, since e does not influence the obligations about p, 
e is different from a, (3, 7 and 5. Then, from (C9) and (CIO) we have: 
Vs(Obg(p,do(e,s)) Obg(p,s )) 

Vs(Obg(-<p, do(e, s)) Obg{^p, s)) 

We see that we obtain frame axioms that have the same semantics in both 
frameworks, the difference is just technical. 

An important issue that deserves more work is the ramification problem, 
that is to integrate in these frameworks invariant constraints between obligations 
like, for example, in the situation calclus \/s(Obg(p, s) —1 Obg{q,s)). Solutions 
proposed by Lin and Reiter in [7] and Mclllraith in [8] could be adapted to the 
case of modal literals. 
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Annex 

Soundness and Completeness 

Soundness of LAPDO can be proved as usual by proving that all the theorems 
are valid, and that the inference rules preserve validity. We prove completeness 
in several steps. 

First we define the set of all instances of axioms ( Persist ) and ( Persisto ): 
Indep(D) = {-■ Preu(a, |L|) — > (L — > [a]L) : a G ACT and L G LIT } 
Indep(DO) = 

{^Pre DO (a, \LM\) -A ( LAI -A \ a]LM ) : a G ACT and LM G LITM} 

We abbreviate Indep(D, DO) = Indep(D) U Indep(DO). 

Let LAPDOq be the basic logic of dependence and obligations such that 
D 0 = DO 0 = {(a, P, T) : a G ACT and P G ATM } 



Lemma. If \=lapdo V then Indep{D, DO) \ =lapdo 0 P- 

This follows from the fact that the class of models of LAPDO is just the 
same as the class of those models p of LAPDOq where Indep(D , DO) is true in 
p. (A set of formulas is true in p iff each of its elements is true in every possible 
world of p.) 

Now we restrict Indep(D) and Indep(DO) to the language of p: 

IndepiyD , DO,p) = Indep{D, DO) fl lang(p) 
where lang{p) is the language of p, i.e. the set of formulas built from the actions 
and atoms appearing in p. 



Lemma. If Indep{D , DO) | =lapdo 0 P then Indep{D , DO ,p) \=lapdo 0 P- 
As Indep(D, DO,p) is finite we can formulate the following. 



Lemma. If Indep{D , DO ,p) \=lapdo 0 P then 

\=LAPDO 0 (□ f\Indep(D,DO,p)) -A p. 




Obligation Change in Dependence Logic and Situation Calculus 



73 



This follows from the fact that Ra contains the reflexive and transitive closure 
of the union of Robg and all the accessibility relations R a . 

In logic LAPDOq we have that Pre_o(a, P) = Prenoi®, P) = T for every a 
and p. Therefore axioms ( Persist ) and ( Persisto ) are redundant in that logic 
and can be dropped. As the remaining axioms are standard ones, the following 
is guaranteed by Sahlqvist’s completeness theorem [13]. 



Lemma. If \=lapdo 0 ( n A Indep(D, DO,p)) -A p then 

I- LAPDOo ( D A Indep(D,DO,p)) -A p. 

Finally we have: 



Lemma. If \~lapdo 0 (□ A Indep(D, DO,p)) — > p then 

Indep{D, DO) \~lapdo 0 ~ t P- 



and 



Lemma. If Indep{D, DO) \~lapdo 0 P then \~ LA pdo P- 

The latter is because the axioms of LAPDO are those of LAPDOq plus 
axioms ( Persist ) and {Persisto)- The set Indep{D, DO) collects all instances 
of the latter axioms. 

Putting the preceding lemmas together we obtain that {=lapdo P implies 
h lapdo P- Hence our logic LAPDO is complete. 

It follows a fortiori that LAPD is complete, too. 
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Abstract. In this paper I propose a simple modification of standard de- 
ontic logic that will enable the system to accommodate deontic dilemmas 
without inconsistency and without deontic explosion, while at the same 
time preserving the range of genuinely valid inferences. The proposal 
applies both to monadic deontic logic and to a dyadic logic of condi- 
tional obligation. In the Appendix these systems are proved to be sound 
and complete with respect to an appropriate semantics and also to be 
decidable. 



In what follows I want to discuss deontic dilemmas and the proper way to treat 
them in deontic logic. In doing so, I shall follow a fairly simple, modest, even 
conservative, course and treat deontic logic as an elementary modal logic of a 
quite ordinary sort 1 . It is my intention to show that such a logic can accommo- 
date deontic dilemmas in a reasonable way despite some objections that have 
been raised, especially by Horty in a number of works, [19], [20], [21]. 

In Section 1 below I will describe what I mean by ‘deontic dilemma’ more 
precisely and the problem that such dilemmas pose for deontic logic. After that, 
in Section 2, I consider briefly some common approaches to this problem that 
appear not entirely adequate. Drawing on lessons seen there, I will present my 
new proposal in Section 3; it should fare better. The discussion to that point 
will concern monadic deontic logic only, since that is the easiest framework to 

1 Hence, throughout this discussion, I suppose a propositional language with formulas 
A in the usual vocabulary, and a single monadic modal operator O to represent ‘it 
ought to be that . . . ’ with OA well-formed whenever A is. (Later I will extend the 
language to include a dyadic operator 0(—/—) for conditional oughts.) I thus use 
the idiom of ought-to-be, which some would distinguish from ought-to-do. I do not 
discriminate between the two since analogous issues arise for both locutions. I also 
abstract from considerations of agency and action, and from such issues as the time 
of an obligation, the authority that institutes it or the person to whom it might 
be directed, if any. These are all significant factors of normative discourse and so 
deserve to be treated in deontic logic. But it is reasonable to suppose that they 
do not have particular bearing with respect to the question of deontic dilemmas 
before us. The same issues should arise with any further sophistication of the logic, 
and should probably be treated in much the same way. Thus, what I present here 
might be taken as a blueprint for a more detailed treatment in richer contexts. In a 
similar vein, I do not distinguish between so-called prima facie oughts and actual, or 
all-things-considered, oughts, since here too similar problems should arise for both. 
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work with, and it suffices to bring out the central issues that the prospect of 
deontic dilemmas raises. Section 4, however, extends these considerations to 
cover conditional obligation. There we will also see how a similar maneuver can 
answer another, separate problem that Horty has raised against ordinary dyadic 
deontic logics. Section 5 concludes with some comparison between the approach 
taken here and Horty’s way of developing deontic logic since Horty put forward 
the objections that have motivated this proposal the most. I reserve for the 
Appendix the full formal presentation of the deontic logics that result from my 
account, their proof theory and semantics, and there establish that the systems 
are sound and complete, and as a side benefit of that demonstration, that they 
have the finite model property and are decidable. 

1 The Problem of Deontic Dilemmas 

By a ‘deontic dilemma’ I mean a situation in which, in a univocal sense of 
‘ought’, some state of affairs, A , both ought to be and ought not to be, in which, 
that is, both OA and 0~>A are true. More broadly, a deontic dilemma would be 
a situation in which there are inconsistent states of affairs, A and B , both of 
which ought to be, that is, a case where hd-> ->B and yet both OA and OB 
are true. More broadly still, a deontic dilemma would be a situation in which 
it is impossible for both A and B to be realized even though both ought to be, 
where the sense of impossibility could be anything appropriate to the context of 
discourse, from some metaphysical impossibility to the most mundane practical 
incompatibility. More generally too, along another dimension, deontic dilemmas 
could be conditional. These would be situations in which both it ought to be that 
A on a condition B , and also it ought to be that not- A on the same condition, 
i.e., where both 0(A/B) and 0(-<A/B) are true, and similarly for the other 
senses of incompatible requirements. 

Of course, the first sense of deontic dilemma is easily seen to be a case of the 
others. In addition, given seemingly innocent assumptions, like the inheritance 
rule, 

RM) If b A -> B then h OA -> OB 

or natural variants of it, then the second broader sense of dilemma reduces to 
the first; i.e., any case of the second will imply a case of the first. Hence, any 
deontic logic that eschews the first sort of dilemma, must eschew the second. 
Similarly, if the sense of impossibility in the third description is such that the 
logic contains anything like 

NM) I — 0(A A —<B) — > (OA — > OB) 

(with O for the appropriate sense of possibility), then the yet broader sense 
of dilemma also reduces to the first, and any logic that eschews the one must 
eschew the other. Hence we can focus our attention primarily on the first sort of 
dilemma, since it is easiest to discuss, though natural examples might take the 
form of the second or third. 
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It is plausible that there are deontic dilemmas, indeed that they are very 
common 2 . I shall not argue that here, however. Instead, I will simply take it 
for granted that there are, or could be, such cases in order to investigate how 
deontic logic should accommodate them. 

Any deontic logic that accommodates deontic dilemmas must, of course, not 
contain the principle 

D) bOd-> ->0->A 

lest it license contradictions. (D) is central to standard deontic logic, SDL, in 
its many variants, and so SDL can be thought of as denying the possibility of 
dilemmas. Or, one might think of commitment to (D) rather as defining the 
range of application of the logic. One might think that, while deontic dilemmas 
might be possible, standard deontic logic only applies to the logic of normative 
systems that are in fact consistent or dilemma- free 3 . Such an approach has severe 
drawbacks, however, and cannot be maintained. Nevertheless, it does suggest a 
measure of adequacy that we might apply to a logic that does accommodate 
dilemmas, namely that it should be equivalent to SDL in case there aren’t any. 
That is, for purposes of this inquiry, we should make minimal changes to SDL 
in order to tolerate deontic dilemmas. One way to put this is to say 

(*) A deontic logic for dilemmas should be such that the result of 
adding (D) as an axiom to it is equivalent to SDL. 

1 think this is a worthwhile criterion, but I do not insist on it. Most proposals to 
accommodate deontic dilemmas do not meet this condition; the one I propose 
below does. 

2 This is especially so when one considers the norms that apply to multiple agents, for 
one agent might be required to do one thing while another agent is required to do 
something else that is incompatible with the first. Think of two players of a game, or 
competitors of any sort. Or think of two people who have each promised something 
which precludes the other’s fulfilling his promise, etc. Of course, since its inception, 
standard deontic logic has denied the possibility of conflicts of obligation, and there 
is a long standing philosophical tradition that argues against the possibility at least 
of moral dilemmas. See Horty [21] for an examination of several such arguments, 
and also Forrester [6] for more sources. Many in that tradition nowadays maintain 
that what look like cases of dilemmas, where it looks as though a person ought 
to do something A and ought to do something else B but can’t do both, are not 
really dilemmas; rather they are situations where it is not the case that the person 
ought to do A and not the case that the person ought to do B, but only the case 
that the person ought to do (A-or-B). I am unconvinced, and all the more so when 
we consider that the agents of the obligations might be distinct. See Routley and 
Plumwood [32] for more discussion of how normative conflicts pervade our lives. 

3 This is analogous to the way one might preserve the inference 

(A) All S are P 

.'. (I) Some S are P 

by saying that the logic that contains it applies only to that part of the language in 
which all terms S have existential import. Cf. Lambert [24], p. 261f. for discussion 
of this, and the reasons why this sort of maneuver should be rejected. I develop this 
theme further below. 
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Any deontic logic that accommodates dilemmas must also not contain prin- 
ciples of ‘deontic explosion’, such as 

DEX) h (OA A O-iA) OB 

which says that if there is any instance of a deontic dilemma then everything is 
obligatory. (And similarly for the other broader senses of dilemma.) It is plausible 
that there are deontic dilemmas; it is not plausible that everything ought to be 
the case. Hence, (DEX) must be rejected. We might make this too a condition 
of adequacy for a deontic logic that can accommodate dilemmas: 

(**) A deontic logic for dilemmas should not contain (DEX), or 
anything like it. 

(In what follows I will be more concerned with (**) than (*).) 

The problem that deontic dilemmas present for deontic logic is simply the 
question of how to avoid deontic explosion, and (D), while at the same time 
accounting for the full range of inferences that do seem valid for normative 
concepts. Any logic that contains the rule (RM) mentioned above and the ag- 
gregation principle 

AND) b (OA A OB) -> 0(A A B) 
and the principle of ex falso quodlibet 

EFQ) h (AA ->A) B 

will ipso facto contain (DEX). Hence, to be adequate for deontic dilemmas, the 
logic must reject or restrict at least one of the principles (RM), (AND) and 
(EFQ). The question is, What is the best way to do that 4 ? 

4 Thus, the problem to be addressed here is the problem of what principles should, and 
should not, be contained in a logic that allows for deontic dilemmas. This should 
be distinguished from the question of how such dilemmas should be resolved, or 
how one should decide to act in the face of such a dilemma. It should also be 
distinguished from the kind of case often envisaged in the literature of defeasible 
reasoning, whereby one might have information that, from a classical point of view, 
seems to lead to inconsistent conclusions, but where some of that information defeats 
the application of other information, so that no conflict is in fact generated. (Birds 
fly; emus are birds; emus don’t fly; Edward is an emu. One concludes that Edward 
doesn’t fly, because he’s an emu; one doesn’t conclude that Edward flies, in spite of 
his being a bird.) Similarly, one might have information that points to the conclusion 
that one ought to do A, but further information that points to the conclusion that 
one ought to do B, when A and B are incompatible, where the latter information 
overrides, or defeats, the former reasoning. (One might think, for example, of sets of 
regulations some of which enjoin A and others forbid A; there might be mechanisms 
of priority that make only one injunction operative in a particular case, so that the 
prohibition of A defeats the injunction for A.) A deontic dilemma is a case where 
neither claim of obligation, OA and OB for incompatible A and B, is defeated; 
both are true. How a deontic logic should accomodate that sort of situation is what 
concerns me here. 
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It is convenient to note that the inheritance rule (RM) is equivalent to the 
converse of (AND) and also to the principle (OR), namely 

M) b 0(A A B) -> (OA A OB) 

OR) b OA 0(A V B) 

given the rule of replacement for equivalents 

RE) If b B then b OA o OB 

which seems a sine qua non for any reasonable deontic logic. That is to say, given 
(RM) then both (M) and (OR) are derivable (and, of course (RE)), and given 
either (M) or (OR), with (RE), then (RM) is derivable. Hence (M) and (OR) 
are equally implicated in the derivation of (DEX). 

2 Some Proposed Solutions 

The problem posed by deontic dilemmas is really two-faced. On the one hand, 
one wants a logic that is not too strong; it must avoid (D), which is easy, and it 
must avoid deontic explosion (DEX), which is also easy, though less so. On the 
other hand, it must not be too weak; it must capture all the inferences one wants 
for the operator O. That second side will become more clear in the discussion 
in Sect. 2.3 below. It is this that makes the problem of deontic dilemmas a 
challenge. 

As noted above, to avoid (DEX), at least one of (EFQ), (RM) and (AND) 
must be rejected or restricted. This suggests three ways one might try to weaken 
standard deontic logic. Let us consider them briefly in turn, with emphasis on 
(AND) since that might be the most common strategy 5 . 

2.1 Reject (EFQ) 

Perhaps the most direct way to avoid the derivation of (DEX) is to deny the 
principle of ex falso quodlibet. This means basing one’s deontic logic on a para- 
consistent logic, rather than the classical propositional calulus, PC, that is usu- 
ally assumed. A natural, and well-developed, alternative is the relevant logic R. 
Routley and Plumwood recommend this in [32], and in my own [7] and [8], I pro- 
posed similar systems for this purpose. I find relevant logic attractive, and think 
that (EFQ) is indeed the real culprit behind deontic explosion. Nevertheless, this 
is a fairly radical departure from standard deontic logics, and requires defending 

5 This will not be an exhaustive review of the proposals that have been made. Van der 
Torre and Tan [35], for example, present an interesting proposal that I do not discuss. 
Theirs is a hybrid that would modify two of the principles, (RM) and (AND), with 
a ‘two-phase’ deontic logic that prevents deontic explosion by not only restricting 
(AND) but also controlling the order of the application of the rules; in effect, this 
distinguishes two senses of ‘ought’ where some standard principles apply to one 
and other principles to the other. While intriguing, this kind of approach goes in a 
rather different direction from the proposal I want to offer, although it may bear 
some similarity to the system I call DPM.2 below. I have not investigated those 
connections, however. 
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an approach to logic in general that goes well beyond deontic considerations. 
(Amongst other things, it requires abandoning such intuitive principles as the 
Disjunctive Syllogism, b (( A V B) A ->A) B.) Rather than enter those battles, 

for present purposes I will simply set this approach aside 6 . 

2.2 Reject Modal Inheritance (RM) 

Keeping all of classical PC, including (EFQ), but denying the rule of monotonic- 
ity or inheritance for O, the rule (RM), and its partners (M) and (OR), will also 
clearly block the derivation of (DEX). Various authors have, for various reasons, 
called this rule into question, e.g., Jackson [23], Hansson [16], [17], pp. 141ff., and 
myself in [9], [10], [11], [13]. Generally speaking, however, the reasons for ques- 
tioning (RM) have little to do with the question of deontic dilemmas, and more 
to do with other paradoxes of deontic logic. Indeed, my own proposals along 
these lines contained (D) and so are incompatible with accepting the possibility 
of deontic dilemmas. 

While I continue to be suspicious of (RM), I will not pursue its wholesale 
rejection here. In a discussion, not of deontic dilemmas, but of the other deontic 
paradoxes, Nute and Yu ([31], p.5) comment on my rejection of (RM), saying, 

But the principle of inheritance of obligations is one of the most funda- 
mental principles of SDL and has strong intuitive appeal. It requires the 
agent to take moral responsibility for the logical consequences of what 
lre/slre has committed to do. The rejection of the principle, therefore, 
seems to be contrary to one of our basic moral reasoning patterns. 

Certainly (RM) does have strong intuitive appeal. Nonetheless, to anticipate 
later discussion, I shall propose modifying it. This will not be a wholesale rejec- 
tion of the principle, as in the works cited above, but rather a limitation on it 
that should take the intuitive appeal of the rule into account. That is the subject 
of Section 3 below 7 . 

6 Other paraconsistent deontic logics are found in da Costa [3] , da Costa and Carnielli 
[4], and Loparic and Puga [27]. Casey McGinnnis, in work as yet unpublished [28], 
[29], presents a variation on this theme with what he calls ‘semiparaconsistent’ deon- 
tic logic. In this, the actual world is construed classically, and validity is determined 
with respect to that world. Hence all of PC is valid, including disjunctive syllogism, 
which gives rise to ex falso. At the same time, however, deontically alternative points 
are construed paraconsistently, in a 3- or 4- valued way. The deontic logic that results 
contains the principles (AND) and (K) of standard deontic logic, but not (D) and not 
(DEX) because it lacks deontic disjunctive syllogism, (0(M VB) A 0~<A) — > OB. As 
a result, this proposal is vulnerable to an objection raised by Horty that is discussed 
in Sect. 2.3 below. (The same is true for deontic logics based on R.) McGinnis’s ap- 
proach also has some peculiar consequences, such as lacking a full replacement the- 
orem (rule (RE)) since (A B) (->A V B) is valid but 0(A — > B) 0(->A V B) 
is not. How much this vitiates the logic is a worthy question. 

7 That proposal does not address the general issues of the standard deontic paradoxes. 
My aim in this paper is to focus entirely on the question of deontic dilemmas and 
deviate as little as possible from standard deontic logic in order to accommodate 
them. 
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2.3 Reject Aggregation (AND) 

Given the strong appeal of (RM) (and complacent attachment to PC, including 
(EFQ)), perhaps the most natural suggestion for avoiding deontic explosion is 
to reject the aggregation principle (AND). In [12], [14] and [15], I recommend 
such a logic precisely for this purpose. I called this logic P. It is axiomatized by 
PC, with closure under modus ponens, the inheritance principle (R.M) and two 
minimal axioms, (N) b O T and (P) I — >0- L, where T is any tautology and _L is 
-iT. Since P lacks (AND), neither (D) nor (DEX) is derivable. (Adding (AND) 
to P yields full SDL, but adding (D) alone does not. Hence P fails condition 
(*)-) 8 ‘ 

P is very well-behaved. It has a natural interpretation in terms of neighbor- 
hood semantics, after Segerberg [34] or Chellas [2], and in terms of preference- 
based models, [12], [14] and [15], as well as in an extension of Kripke-models, 
[12], [33]. Nevertheless, it is a very weak deontic logic, perhaps too weak. This 
is the concern to which I alluded as the second face of the problem posed by 
deontic dilemmas. It is this that motivates the present discussion. 

Van Fraassen [37] and after him Horty [19], [20], [21] have argued that systems 
like P fail to account for patterns of inference that seem unobjectionable and 
that seem to require the principle of aggregation (AND). Horty frequently gives 
the example of a person, perhaps a conscientious objector, who recognizes the 
obligations for someone, Smith, 

i) Smith ought to fight in the army or perform alternative service 
to his country — 0(F V S) 

ii) Smith ought not to fight in the army — 0~>F 

and who then reasons to the conclusion 

iii) Smith ought to perform alternative service to his country — OS 

Whether this is a case of Smith deliberating for himself what he should do, or 
someone else describing the situation that pertains to Smith, the inference from 
(i) and (ii) to (iii) seems valid. Given the principle of aggregation, that is easy to 
explain. By (AND), (i) and (ii) entail 0((F\/S)A->F). Since b ((FVS)A->F) — > S, 
b 0((F V S) A -.F) -)• OS, by (RM). So, given 0((F V S') A F), (iii) OS 
follows. Nothing in P licenses this inference, however, and this seems a significant 
shortcoming of the system and others like it. 

It is considerations like this that make the problem of deontic dilemmas a 
difficult problem. How can one steer a middle course between a normal logic 
like SDL, or even K, which are clearly too strong, and a minimal logic like 

8 Others have also proposed this, or a very similar system, for the same purpose. For 
example, Schotch and Jennings [33] likewise introduced the same system in order to 
allow for deontic dilemmas. P is very like the first system van Fraassen proposed in 
[37], p. 16, though he backed away from it for reasons we will discuss below. P differs 
from van Fraassen’s in that P contains (N) while his does not, but I take this to be 
an insignificant difference; (N) fails only in models in which nothing is obligatory. 
Chellas [2], p. 202 proposes the same system as van Fraassen’s first as a minimal 
deontic logic; this too in order to permit deontic dilemmas. 
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P, which appears to be too weak? Since aggregation (AND) seems to be what 
distinguishes P from SDL, perhaps there is a way to restrict (AND) without 
rejecting it altogether. 



2.4 Restrict Aggregation 

Here we look at three ways to limit the aggregation principle; at least two of 
them won’t work. 



2.4.1 Consistent Aggregation. A first natural suggestion for a way to ac- 
commodate both situations in which there are deontic dilemmas and the cases of 
innocent inferences using aggregation is to adopt a principle that allows OAl\OB 
to entail 0(AA B) except when that would get one into trouble, as when A and 
B are incompatible, which, as we have seen, would lead to deontic explosion, 
not to mention a violation of principle (P). Hence, it seems plausible simply 
to restrict aggregation to those cases where A and B are consistent (or jointly 
possible). Call this the principle of Consistent Aggregation or 

ConAND) If V- A -> then b (OA A OB) 0(A A B) 9 

While this move might seem natural 10 , (ConAND) is still too strong and will 
not serve as it is supposed to. Here is a counterexample (adapted from Horty 
[21] p. 581). Suppose a situation in which someone, Jones, ought to visit his 
daughter Abby at a certain time — OV a . It is plausible that in this situation he 
should notify her he is coming and then visit her 0(V a A N a ). But it could 
also be that in the very same situation Jones ought also to visit his daughter 
Beth at that same time, and indeed that he should notify her he is coming and 
then visit her 0(14 A N b ). Because of circumstances, however, such as that 
Abby and Beth live on opposite sides of the country, it is impossible for Jones to 
visit both at that time. Thus he faces a deontic dilemma. Both 0(14 A N a ) and 
0(Vb/\Nb ) are true, though presumably 0((14A N a ) A (14 A A4)) is not. But from 
0(14 A N a ), ON a follows by (RM), and similarly ON b follows from 0(14 A N b ). 
N a and N b are consistent; hence they are candidates for (ConAND). Since both 
ON a and ON b are true and N a and N b are consistent, it follows by (ConAND) 
that 0(N a A N b ) is true, that Jones ought to notify both his daughters he is 
coming to visit, and indeed that he ought to notify both that he is coming even 
if he only goes to see one of them. That seems going too far. 

9 As with the principle (NM), mentioned in Sect. 1, if the language has alethic 
modalities, this rule might be replaced with a stronger postulate h 0(4 A B) — > 
(( OA A OB) — » 0(A A B)), with O for any appropriate sense of possibility. All the 
remarks to follow would apply mutatis mutandis to this as well. 

10 I know of no published source that adopts this rule, and for good reason. Never- 
theless, it is the sort of proposal that comes to mind first when considering how to 
handle deontic dilemmas. At least, it has come up often in conversations. (Van der 
Torre and Tan [35], p. 411 attribute this principle, with this name, to van Fraassen 
[37], but I do not find it there.) 
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Jorg Hansen presented a similar problem for a version of (Con AND) proposed 
by Paul McNamara. As McNamara [30] presents the example, the story goes like 
this (with free use of alethic modalities) : Suppose a person ought to do something 
A that necessitates something else C, and likewise ought to do something B that 
necessitates D , when A and B are incompatible but C and D are not. With 
(ConAND) one then infers 0(0 AD), which has no support in the situation. For 
example, Jones ought to keep an appointment in Montreal on Monday morning 

( OA ) and Jones ought to keep an appointment in London on Monday afternoon 

(OB) , where we may assume it is impossible for Jones to do both, given the 
distances (->0(A A B)). Hence there is a dilemma. To keep the appointment 
in Montreal necessitates traveling to Montreal in the morning (D(A — > C)), 
while keeping the appointment in London necessitates departing for London in 
the morning (□(£? —> D )). It is, however, possible to travel to Montreal in the 
morning and depart from there for London, (0(C A D)). With (RM) one can 
then infer first both OC and OD, thence 0(0 A D) by (ConAND). But that 
seems contrary to the facts of the case. 

Examples like this should make one suspicious of (ConAND). Moreover, we 
can make a stronger, more general case against this rule 11 . Consider a case of 
a deontic dilemma where we suppose OA and 0~>A to hold, and let B be any 
consistent proposition, so that Y B. We show that OB. B must be consistent 
with either A or —>A\ suppose it is ~>A, so that Y B — > A, and argue: 



i) 


OA 


hyp 


ii) 


0~<A 


hyp 


iii) 


Y B 


hyp 


iv) 


Y B^ A 


hyp 


v) 


0(A V B) 


i, PC, RM 


v |) 


Y (A V B) — > —i—i A 


iv, PC 


vii) 


0((AV B) /\^A) 


ii, v, vi, ConAND 


viii) 


b ((A V B) A —‘A) B 


PC 


ix) 


b 0((A V B) A -i A) OB 


viii, RM 


x) 


OB 


vii, ix, PC 



In case B is consistent with A the argument is similar, and so we may discharge 
the hypothesis at (iv). Thus we conclude that if there is any deontic dilemma, 
then anything consistent is obligatory. Call this rule: 

DEX-1) If Y B then b (OA A O^A) OB 

(DEX-1) does not go quite as far as full deontic explosion (DEX) that follows 
from full aggregation, where B could be anything at all, but it is still absurd. 
It still means the collapse of normative distinctions in plausible circumstances. 
Moreover, B could easily be taken to be something specified to be normatively 
neutral, and then there would be a direct contradiction. Clearly then, an ade- 
quate deontic logic must reject (DEX-1) no less than (DEX). Hence, consistent 
aggregation, (ConAND), is far too strong, not much better than complete ag- 
gregation, (AND), itself. 

11 Van der Torre and Tan [35], p. 412, observe much the same. 
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2.4.2 Weakened Consistent Aggregation. The logic that Horty [21] presents 
to countenance deontic, or moral, dilemmas does not satisfy consistent aggrega- 
tion. Instead it supports a weaker rule he calls ‘consistent consequent agglom- 
eration’. Just what this is, is difficult to describe without more machinery than 
we have available. Very roughly, Horty’s account goes like this (but see [21] for 
details). First, he distinguishes two sorts of ‘ought’; one, represented by formulas 
!(A), is for prima facie oughts, perhaps derived directly from imperatives. The 
other, represented by formulas 0(^)> is f° r the all-things-considered ought 12 . 

Horty’s question is how such all-things-considered oughts are derived from 
sets of prima facie oughts, especially in the face of moral conflicts. His answer, 
very roughly, is that 0(^4) follows from a set X of prima facie oughts just in 
case A is a logical consequence of a maximal consistent subset of the appli- 
cable binding prima facie oughts in X. The rule of consistent consequent ag- 
glomeration (CCA) can now be (roughly) stated: Suppose a number of oughts 
O(-Bi), . . . , O (Bn) are consequent on a set of prima facie oughts X, then the 
aggregate Q(Bi A • • • A B n ) is consequent on X just in case the set {B\ , . . . , B n } 
is both (i) consistent and (ii) a subset of the set of propositions enjoined by the 
binding members of X. (Cf. [21] p. 580.) 

Condition (i) of (CCA) is like the rule of consistent aggregation; condition 
(ii) lets (CCA) escape the problems that confronted that rule. In the example 
of Jones visiting his daughters, we can suppose that the setup is such that the 
relevant set of prima facie oughts X is {\{V a A N a ), !(V), A iV&)} and that both 
are binding on Jones. From this set, both 0(V a A N a ) and O (ki A iVj) follow, 
though 0((K A N a ) A (Vb A Nb)) does not, just as we should want. And neither 
does 0(N a A Nb), for the set {N a ,Nb}, though consistent, is not a subset of 
the propositions enjoined by the members of X since neither \N a nor LA), is in 
I. (Both O (N a ) and O (Nb) would, however, follow from I, but their aggregate 
Q)(N a A Nb) does not, which is the key point now.) Hansen’s example would 
be treated similarly, as would the more general problem that led to (DEX- 
1). The crucial step there is step (vii), but this cannot be inferred from (ii) 
and (v) by (CCA) even given (vi) since {A V B, ->A} is not a subset of the 
propositions enjoined by the operative set of background oughts, which we can 
take now to be just !(A) and !(-n4). By contrast, when aggregation is wanted, 
it is available. Thus in the example of Smith and his service to his country, let 
us suppose the operative set of prima facie oughts X is {!(.F V S), \(~<F)} and 
that both are binding. Then Q)(F V S) and O (^F) follow from X, and so too 
does C)((F V S) A ~<F) since {(FV S),~<F} is a consistent subset of propositions 
enjoined by the binding oughts in X. From this Q)S follows since (RM) holds for 
O hr Horty’s system. 

Thus the rule (CCA) seems to do what is asked of it. Moreover, if there are 
no deontic dilemmas, i.e., if the background set X of prima facie obligations is 



12 Horty [21] actually sets everything up for conditional oughts, of both kinds, to have 
formulas \(B/A) and Q(B/A), each to say in its sense that under conditions A, it 
ought to be that B. B here is the ‘consequent’, which explains the name of Horty’s 
rule. The present monadic simplification will suffice for our purposes. As is custom- 
ary, !(A) and O(A) are defined as !(A/T) and 0(A/T), respectively. 
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conflict free, then Horty’s system agrees with SDL; this seems a desirable feature, 
not found in systems that deny (EFQ), or (R.M) or (AND) 13 . 

We might find further philosophical support for this sort of approach as 
follows. Consider familiar accounts of the Kripke-style semantics for standard 
deontic logic. There OA is said to hold at a possible world just in case A holds 
at all the ‘ideal’ or deontically ‘best’ possible worlds (accessible from the given 
world). A possible world is typically considered ideal insofar as it is a world 
where all obligations are fulfilled (cf. Hilpinen [18], p. 163). If there are deontic 
dilemmas, however, there can be no ideal worlds in this sense (so long as we keep 
to a classical view that possible worlds are entirely consistent). But we might 
still think that a world is ideal, not perhaps when all obligations are fulfilled, 
but when all that can consistently be fulfilled are, when the world is as good 
as it can be. That is, we might think of a world as ideal just when a maximal 
consistent set of obligations are fulfilled in it. This might be thought of as a 
semantic counterpart to Horty’s picture. 

Unfortunately, there does not seem any way to realize this picture in a 
straight-forward possible-worlds type model theory for deontic logic. Although 
we explain the idea of an ideal world in terms of the obligations that obtain in a 
given world, to define truth conditions for formulas OA we must take the notion 
of ideal world as primitive. If we were to say that OA is true at a possible world 
just in case A is true at all ideal worlds, we are back in the original fix that 
either there are no ideal worlds, in which case deontic explosion is validated, or 
else there are, in which case (D) is validated. If we were to say that OA is true 
just in case A is true in some ideal world, we lose the validity of the inference 
concerning Smith’s obligations to his country, inferences with deontic disjunctive 
syllogism when there is no conflict of obligation involved. 

Horty himself does not try to present his system in this sort of possible- 
world/model-theoretic terms, and indeed it is considerations like this that lead 
him away from thinking of deontic logic in the framework of traditional modal 
logics. His proposals require a rather radical rethinking of the foundations for de- 
ontic logic. Not being able to implement the modified semantic picture of ideal 
worlds suggested above, does, however, point to a limitation of the approach 
Horty has taken. He himself remarked that condition (ii) of his rule of consistent 
consequent agglomeration may seem “peculiar, or at least excessively syntactic” 
([21] p. 580). This limits aggregation to cases determined by the particular spec- 
ification of the prima facie oughts in X. It means, amongst other things, that 
X cannot be considered closed under logical consequence. If it were, then given 
!(U 0 A N a ) £ X and given !(Vj, A Nf,) £ X , we should have \N a £ X and INt £ X, 
and then (f)(N a A Nb) would follow from X. Similarly, if !(A V B) followed from 
!(A), then the problem that gave rise to (DEX-1) would reappear. This suggests 
that, although Horty has given an account of how all-tlrings-considered oughts 
follow from specific sets of prima facie oughts, this account leaves no room for 
a logic of prima facie oughts themselves. 

13 Cf. the criterion of adequacy (*) of Sect. 1, though we won’t go so far as to say that 
Horty’s system plus (D) is equivalent to SDL because they are too different in their 
fundamentals. 
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2.4.3 Permitted Aggregation. The rules of consistent aggregation (ConAND) 
and consistent consequent agglomeration (CCA) screen candidates for combina- 
tion by conjunction through the logical property of consistency (or more broadly 
possibility). In place of that one might consider screening for normative consis- 
tency (or normative possibility). This is simply the notion of (joint) permis- 
sibility, which is already available in the language. Then one could say that 
aggregation is permitted, as it were, when the aggregate is itself permitted. This 
would be the rule 

PAND) \- P(AaB)^((OAaOB)^0{AaB)) 

where, as usual, PA =df ->0~>A. This rule could then be added to the logic P 
to form the system PA 14 . 

Consider how PA handles the previous examples. For the case of Smith and 
his service to his country, one wants to infer 0((FV5)A ->F) from 0(F V S) and 
0~>F in order to conclude OS. Implicit in the example is that it is all right, i.e. , 
permitted, that Smith perform alternate service to his country and not fight in 
the army; without that, the example has no intuitive appeal. Thus we can take 
P{—>F A S') as an implicit premise in the setup. So we have given 

i) 0(F V S ) hyp 

ii) 0~>F hyp 

iii) P(-<F A S) hyp 

and reason as follows: -> F A S is logically equivalent to (F A ~<F) V (->F A S), 
which is logically equivalent to (F V S) A ->F, hence 



iv) 


P((F V S') A -hF) 


iii, PC, RM 


v) 


0((F V 5) A -<F) 


i, ii, iv, PAND 


y i) 


b (F V S) A ->F) -A S 


PC 


vii) 


b 0((F V S) A ->F) -»• OS 


vi, RM 


viii) 


OS 


v, vii, PC 



which seems to be just the argument one has in mind with examples like this. 

In the case of Jones notifying his daughters he is coming to visit, for the 
example to count against consistent aggregation (ConAND) it must be assumed 
that there is something wrong with his notifying them both (when he will visit 
at most one). That is, implicit in the setup is the proposition that 0-i(N a ANb). 
If that is so, then we are given -> P(N a ANi ,), and so we cannot have the condition 
necessary to apply (PAND) to infer 0(N a A Nt,) from ON a and ON j, under pain 
of having a contradictory premise set. 

A similar point applies to the general problem that gave rise to (DEX-1) in 
Sect. 2.4.1. Suppose we are given OA and 0~>A and we take some proposition B 
that is supposed to be not only logically consistent (compossible) with -i A (or A 
as the case might be) but normatively consistent with it. That is, let us assume 

14 This system is new. I once thought that, since (PAND) is properly weaker than 
(ConAND), it would be an adequate way to accommodate deontic dilemmas, but, 
as we shall see, it is not. Nevertheless, I present it here in part as a cautionary tale, 
and also as a step to the new proposal I will develop in the next section. 
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P(B A -u4), and try to run the argument as before, with this assumption as line 
(iv) ( (iii) drops out), and the counterpart of line (vi) following by the logical 
equivalence of B A —>A and (A V B) A —>A. Then line (vii) seems justified by the 
new rule (PAND). Thus: 



i) 


OA 


hyp 


ii) 


OhA) 


hyp 


iv) 


P(B A -A) 


hyp 


v) 


O(AVR) 


i, PC, RM 


v |) 


P((4VB)And) 


iv, PC, RE 


vii) 


0((A V B) A ->A) 


ii, v, vi, PAND 


viii) 


b ((A V B) A ->A) — > B 


PC 


ix) 


b 0((A V B) A ->A) OB 


viii, RM 


x) 


OB 


vi, ix, PC 



(The argument would be similar if B were co-permissible with A instead of -iA, 
i.e., with P(B A A) in place of P{B A ~>A) at line (iv).) 

At first sight then (PAND) would seem to suffer the same sort of failing as 
(ConAND): if there is any deontic dilemma then anything co-permissible with 
one of the obligations is itself obligatory. This is not so, however. For as we 
look more closely at what we are given in (i), (ii) and (iv), we see that (i) OA 
entails 0(B — > A), by (PC) and (RM); hence it entails the logically equivalent 
0^(B A “'A), which is to say, ->P(B A -> A). Thus (i) and (iv) are contradictory 
assumptions. It is no wonder then that untoward consequences, e.g., (x), follow 
from them. So long as the premise set of the argument is consistent, no problem 
should arise. Or so it might appear. So PA might seem an appropriate logic for 
deontic dilemmas. 

Unfortunately, this proposal really fares no better than the rule (ConAND) 
above, for like (ConAND), (PAND) also yields a form of deontic explosion, 
namely that if there is any case of a deontic dilemma, then anything that is 
permitted will be obligatory, which seems absurd. 

The argument for this consequence is much like the argument against the 
principle of Consistent Aggregation (ConAND) that was given above. Suppose 
a deontic dilemma, OA and 0->A, and a proposition B such that PB. 



i) 


OA 


hyp 


ii) 


O-iA 


hyp 


ih) 


PB 


hyp 


iv) 


0(A V B) 


i, PC, RM 


v) 


0(—<A V B) 


ii, PC, RM 


v |) 


b ((A V B ) A (->A V B)) 


PC 


vii) 


P((A V B) A (->A V B)) 


iii, vi, RE 


viii) 


0((A V B) A (-iA V B)) 


iv, v, vii, PAND 


ix) 


OB 


vi, viii, RE 


x) 


b (OA A 0~>A) (PB OB) 


i-ix, Conditional Proof. 
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Call the principle (x) here 

DEX-2) b (OA A O-iA) ( PB OB) 

Though weaker than the original (DEX) and (DEX-1), this too seems absurd, 
and contrary to the spirit of accepting deontic dilemmas. It is enough to bar 
(PAND) and so the system PA. Moreover, the pattern of this argument would 
seem to generalize. As applied to the principle of Consistent Aggregation, it 
showed that if there is a deontic dilemma then any proposition that is consistent 
(or possible) is obligatory. As applied here, it shows that if there is a deontic 
dilemma then any proposition that is permitted is obligatory. Consider then 
any proposed restriction on the principle aggregation, a principle that if OA 
and OB and Cond(A, B), then 0(A A B), where Cond(A 1 B) is some condition 
to be met by A and B together to reflect the limitation of aggregation, such 
as mutual consistency, compossibility, or co-permissibility, etc. If Cond(A, B) is 
such that it is appropriate to speak of its applying to a single proposition, B, 
or that Cond(B , B) could hold, especially if this is given as a modality on the 
conjunction of A and B , and if this condition or modality is preserved under 
replacement for logical equivalents, then the preceding sort of argument would 
seem to apply, regardless of the particular condition. If the condition is such that 
it is plausible that a proposition could meet it without being obligatory, then 
the restricted principle of aggregation based on it will be in trouble. This should 
cast doubt on any attempt to accommodate deontic dilemmas by limiting, but 
not excluding, aggregation (AND) 15 . 

3 Another Proposal: Permitted Inheritance 

In this section I present my new proposal, drawing on the discussion of Per- 
mitted Aggregation, but redirecting its device. That is, instead of limiting the 
aggregation rule (AND), I propose to limit the inheritance principle (RM). The 
idea behind (ConAND), (CCA) and (PAND) was that aggregation should be 
allowed except in cases where it gets one into trouble, by producing deontic ex- 
plosion, (DEX) or its variants. The same idea can be applied to the inheritance 
rule. Thus, I propose to replace the rule (RM) with 

RPM) if b A -> B then b PA —> (OA -> OB) 

where, as before, PA =df - 1 O- 1 A. Thus, if A entails B then if one ought to do 
A then one ought to do B, provided that A is permitted or consistent with the 
normative code. (Or, since hdf> (AAB) when b A — > B, this could be phrased 
in terms of the conjoint permissibility of A and B , as in (PAND), but that is 
not necessary.) 16 . 

15 This remark does not apply to Horty’s rule (CCA), which operates in a significantly 
different framework. 

16 As with (NM) and (ConAND), adapted in Footnote 9, this rule too can be strength- 
ened to b D(A — > B) — » (PA — » (OA — » OB)) if the language contains alethic 
modalities with □ for an appropriate necessity. 
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Since this rule is weaker than (RM), we cannot simply add it to the weak logic 
P, as with rules like (ConAND) or (PAND). Instead, let us build a system from 
scratch. There are two plausible variations for how this could be done. I present 
them both. Let DPM.l, the first Deontic logic with Permitted Inheritance, be 
given by adding to classical PC, with closure under modus ponens, 

RE) if b B then b OA^OB 

RPM) if b A ^ B then b PA -» {OA OB) 

N) b OT 

AND) b {OA A OB) -> 0{A A B) 

(RE) is simply a replacement rule for logical equivalents; I consider it a 
prerequisite for any plausible deontic logic, regardless of the question of deontic 
dilemmas. To do without it, or to restrict it in the manner of (RPM), would mean 
that assertions of obligation would depend for their truth value on the particular 
syntactic structure of their embedded formulas. In systems with unrestricted 
(RM), (RE) is derivable; here it must be postulated separately. (N) is included 
here primarily so that the logic will approximate SDL; given (N) and (RE), 
the rule form of necessitation (RN), If b A then b OA , is derivable. One might 
dispense with either form, but given (RPM), and PC, alone, b (OAaPA) —>■ OT 
would be derivable. Thus, if there were anything that was both obligatory and 
permitted, i.e., any case of a non-conflicted obligation, as no doubt there is, then 
the tautology T would be obligatory. So one gains very little by not including 
(N) as stated. RPM.l has an unrestricted principle of aggregation (AND), yet 
it will still avoid (D) and especially deontic explosion (DEX) (as well as (DEX-1) 
and (DEX-2)). Because it has (AND) without restriction, RPM.l must then 
not posit (P), I — 'OT, since otherwise (D), I — *{OA/\O^A) would be derivable, 
contrary to our desire to allow for deontic dilemmas. 

If one wanted (P), in order to maintain that although there could be conflicts 
of obligation, there could be no obligatory contradictions, ‘ought’ implies ‘can’ 
and all that, then one could restrict (AND) along the lines of (PAND) in Sect. 
2.4.3 above. This yields the second variation DPM.2, given by 

RE) ifbAoB then b OA -fA OB 

RPM) if b A ^ B then b PA -a {OA -a OB) 

N) b OT 

P) b -■OT 

PAND) b P{A AB)a {{OA A OB) 0{A A B)) 

In this system too, neither (D) nor (DEX), or its variants, is derivable. Hence 
both are candidates for a logic that admits the possibility of deontic dilemmas. 
I will use the term DPM when remarks apply equally to both versions. (One 
might also weaken DPM.2 by not including (P) while keeping the restricted 
(PAND); the remarks below will apply equally to this minor variation.) 

Neither version of DPM contains the distribution principle (K), 0{A — >■ 
B) — >■ {OA — >■ OB). If it did, then the unrestricted inheritance rule (RM) would 
be derivable, and then (DEX) (or (DEX-2)) would reoccur, and DPM.2 would 
contain (D) and be equivalent to SDL. That (RM) is derivable given (K), is very 
quick from (N) and (RE): 
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i) 


bJ->B 


hyp 


ii) 


b (A -> B) o T 


i, PC 


iii) 


b OT 


N 


iv) 


b 0(A B) 


iii, RE 


v) 


b OA^OB 


iv, K 



But even without (N), unrestricted (K) would yield the rule: If b A — > B then 
b (OC A PC) — > (OA — > OB), and from this another form of deontic explosion 
would follow, namely 

DEX-3) b (OC A PC) -A ((OA A 0->A) —> (PB -> OB)) 

This says that if there were anything that was both obligatory and permitted, 
any non-conflicted obligation, as there surely is, then if there were any deontic 
dilemma, then whatever is permitted is obligatory. (Derivation is left to the 
reader for fun.) While less than full (DEX), (DEX-3) is still unacceptable. Hence 
(K) too is unacceptable in this context. 

Although (K) is unacceptable, and not derivable in DPM, this restricted 
form, ‘permitted (K)’, is derivable: 

PK) b P(A A B) (0(A B) (OA -> OB)) 

This follows with (RPM) and either unrestricted aggregation (AND) or permit- 
ted aggregation, (PAND). Likewise, given (PK), along with (N) and (RE), the 
rule (RPM) can be derived. Hence, either might be taken as primitive. (Deriva- 
tions are left to the reader.) 

I will present DPM in full formal dress in the Appendix, where I will also 
demonstrate the claim that indeed neither (D) nor (DEX), including the several 
variations described above, is derivable. There I will prove that the systems are 
sound and complete with respect to an appropriate semantics, and also that they 
are decidable. In the meantime, let us consider informally how DPM responds 
to the concerns raised for the other systems. 

With the failure of (D) and (DEX) in its several forms, one primary issue 
is clearly resolved. Both versions of DPM are able to tolerate deontic dilem- 
mas. Moreover, they escape the problematic cases from Sect. 2.4.1 that arise 
for systems with Consistent Aggregation (ConAND), such as the scenario of 
Jones visiting his daughters and Hansen’s example of traveling to Montreal and 
London. 

For logics with the rule (RM) if there is a case of a deontic dilemma where 
OA and OB are both true but A is incompatible with B , it follows that OA and 
0~iA are both true, and so there is a dilemma in the narrow sense. This result 
does not quite hold for DPM, but something similar does, namely that if OA 
and OB are both true and A and B are incompatible, then either OA and 0~>A 
are both true or else OB and 0~>B are both true. Hence, if there is a deontic 
dilemma, then at least one of the conflicting obligations is itself conflicted; either 
OA and ->PA holds or else OB and -> PB holds. This will suffice to block the 
application of (RPM). Thus, with Jones and his daughters, we are given that 
0(V a A N a ) and 0(14 A Nb) when it is impossible to have both V a A N a and 
Vb A Nb (because it is impossible to have both V a and 14) . This posed a problem 
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for (ConAND) because, with (RM) one could infer both ON a and ON &, and 
then the undesirable 0(N a A Nb) follows since N a and Nb are jointly possible. 
With (RPM) in place of (RM), however, one cannot infer both ON a and ONb 
since, by the above, one will not have both of the initial conditions P(V a A N a ) 
and P(Vb A Nb) that are required for the two applications of the rule. Hence, 
even with the unrestricted aggregation rule (AND) of DPM.l, the unwanted 
0(N a A Nb) is not derivable. 

Similar remarks apply to Hansen’s example. Granted that Jones ought to 
keep the appointment in Montreal and also ought to keep the appointment in 
London (OAaOB) though it is impossible to do both (~<0(AAB)), we know, by 
the remark above, that either —>PA or —> PB. Hence, even though keeping each 
appointment necessitates the described travel (D(A —> C) and U{B -A D)), 
the inference to either OC or OD by (RPM) will be blocked since the requisite 
clause concerning permission will be missing. Thus there can be no inference to 
the unwanted 0(C A D) from the initial premises. 

Thus the logics DPM avoid not only deontic explosion, but also the other 
untoward cases that troubled earlier proposals. So it seems these logics are not 
too strong. The real question, though, is whether they are too weak, as, for 
example, the system P seemed to be. Since these systems restrict (RM), and 
since (RM) has strong intuitive appeal (cf. the comment of Nute and Yu in Sect. 
2.2), won’t DPM automatically fail to capture all the inferences one expects? 
Further, is DPM adequate to represent the sort of inference that was brought 
against the system P, which originally raised this concern? 

Regarding the intuitive force of (RM), this seems drawn from considering 
cases in which the antecedent A of the entailment will be considered (norrna- 
tively) consistent, and thus the intuitive support for a rule of inheritance applies 
to (RPM) rather than the unrestricted (RM). I strongly suspect we have no clear 
intuitions about inheritance in conflict cases; at any rate, I have none. And thus 
the limitation on the rule does not automatically mean the system is too weak; 
more argument would be required. 

Here is an analogy to illustrate what the restriction on the inheritance prin- 
ciple accomplishes. Consider free logic 17 . In classical first-order logic, the rule 

UI) a) MxAx 
b) At 

is valid for all individual constants t. And it certainly has strong intuitive ap- 
peal. Nevertheless, the free logician maintains that (UI) is not valid; it fails in 
cases where the individual constant t does not refer to anything that exists. For 
example, the argument 

a) For all objects, x, there is an object, y, identical to x. — 

Mx3y(y = x) 

b) There is an object y identical to the planet Vulcan. 

3 y{y = Vulcan) 

17 See, e.g., [24] for a useful introduction to this kind of logical system and its motiva- 
tions. 
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has a true premise and a false conclusion. (The quantifiers here are construed 
classicially, as ranging over existent entities.) The plausibility, the intuitive ap- 
peal, of (UI) derives from the presupposition that the singular term t refers to 
an existent. By adopting this rule, classical logic, in effect, limits its range of 
application to languages containing no terms that fail to refer in this way. This 
is a severe limitation. 

In its place, the free logician recommends letting the language contain sin- 
gular terms that lack existential import, but build the presupposition required 
for the application of (UI) into the rule itself. Thus, although free logic rejects 
(UI), it accepts the restricted rule 

RUI) a) VxAx 
c) t exists 
.'. b) At 

With the logics DPM I recommend something analogous. We accept in- 
ferences based on deontic inheritance (RM) (and perhaps aggregation (AND)), 
we find that they have strong intuitive appeal, under the presupposition that 
the situations described are conflict free. Standard deontic logic, with its unre- 
stricted rule (RM) and (AND) , in effect limits itself to reasoning with normative 
structures that exclude deontic dilemmas. This is a severe limitation. In its place 
I propose that we recognize the possibility of such conflicts, and then build the 
presupposition required for the application of the rule into the rule itself. That 
is what (RPM) does. Given that A entails B, we accept that OA entails OB , 
provided that the obligation that A is not itself conflicted. 



That is just how DPM treats arguments like that of Smith’s obligation to 
serve his country. This follows the pattern described in Sect. 2.4.3 for PA to 
illustrate the restricted rule of permitted aggregation (PAND). We are given 
that Smith ought to fight in the army or perform alternate service — 0(F V S) 
and that he ought not to fight in the army — 0~>F — and we take it as an 
implicit premise that it really is all right, i.e. , permitted, that Smith not fight 
but perform alternate service — P(-<F A S). We then argue that Smith ought 
to perform alternate service (OS) as follows, in DPM.l: 



i) 0(F V S) 

ii) 0~>F 

iii) P(->F A S) 

iv) b (~>F AS)f> ((F VS) A ->F) 

v) P((FV S) A^F) 

vi) 0((F V S) A ~>F) 

vii) b (F V S) A -,F) -A S 

viii) b P((F VS) A ->F) -V (0((F VS) A -.F) -► OS) 

ix) OS 



hyp 

hyp 

hyp 

PC 

iii, iv, RE 
i, ii, AND 
PC 



vii, RPM 
v, vi, viii, PC 



In DPM. 2 the argument would insert a step by (PAND) 

v)' P((F VS) A -iF) 0((F VS) A ->F) i, ii, PAND 



between (v) and (vi) and then conclude (vi) by modus ponens from (v). 
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Thus these systems seem well equipped to handle arguments like this, pro- 
vided one is prepared to accept the implicit premise (iii). I will return to this in 
the Conclusion below. 

Finally, it is worth noting that in case there were no deontic dilemmas, no 
violations of (D), then DPM.l would agree wholly with SDL. That is, if (D) 
were added as an axiom to DPM.l, the result is equivalent to SDL. (Criterion of 
adequacy (*).) Oviously all of DPM.l + (D) is contained in SDL. The converse 
follows from the fact that (RM) is derivable given (D) with (RPM). Thus: 



i) hyp 

ii) b PA — »■ (OA — > OB) i,' RPM 

iii) b OA PA D 

iv) b OA — > (OA — > OB) ii, iii, PC 

v) bOA-> OB iv, PC 



Hence, DPM.l + (D) contains (RM), (N), (D), and (AND), which are adequate 
for SDL. Therefore DPM.l + (D) is equivalent to SDL. 

This is not so for DPM.2. Although the derivation of (RM) from (RPM) and 
(D) still holds, the full proposition (AND) does not follow just given (PAND), 
along with (D) and (RM), etc. Thus, in a sense, DPM.2 does not correspond 
to SDL in a dilemma free universe. But even so, I suspect, though will not 
argue, that DPM.2, with its limited principle of aggregation, would still appear 
adequate in such a case. 

4 Conditional Obligation 

So far I have only discussed monadic deontic logic because that is simplest, 
and suffices to raise the question of the proper way to accommodate deontic 
dilemmas. Nevertheless, since so much of normative discourse seems to require 
a notion of conditional oughts, it is worthwhile to extend the previous consider- 
ations to apply to them. Thus, when speaking of deontic dilemmas, we should 
include cases in which some state of affairs B is enjoined under a condition A, 
0(B/A ), and so is ~^B, 0(^B/A), or more generally situations in which 0(B/A) 
and 0(C/A) when B and C are jointly impossible, given A. Formulas 0(B/A) 
may be read ‘it ought to be that B under the condition A. 

Given an operation of conditional obligation 0 (— /— ), the monadic operator 
0 (— ) can be introduced by definition so that OA =df 0(A/ T), and then one 
should expect the logic of such a defined monadic ‘ought’ to be the same as one 
has originally settled on. Indeed, the logic for 0(— /A) should also be the same 
for any condition A held constant, (or perhaps any consistent condition; there are 
subtleties that can arise when A is inconsistent). These considerations suggest 
that a proper logic of conditional obligation that will accommodate (conditional) 
deontic dilemmas will contain at least the principles, corresponding to DPM.l: 
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RCE) If h A o B then h 0(C/A ) o 0(C/B) 

CRE) If h B^C then h C>\b/A) o o\c/A ) 

CRPM) If h B -4 C then h P(B/A) -> (0(B/A) 0{C/A)) 

CN) h 0( T/T) 

CAND) h ( 0(B/A ) A 0(C/A )) -»• 0(B A C/A) 

where P(B/A) = d f -<0(-<B/A). Call the result of adding these to PC, and 
closing under modus ponens , CDPM.l. The first rule is the rule of replacement 
of equivalents in the antecedent position. The remaining postulates correspond 
directly to those of DPM.l. For CDPM.2, the counterpart to DPM.2, add 

CP) h ->0(±/A) 
and replace (CAND) with 

CPAND) h ( 0(A/C ) A 0{B/C ) A P((A A B)/C)) -► 0{(A A B)/C) 

Beyond these minimal principles there is opportunity for a lot of variation 
for the logic of conditional obligation, especially in the way it manipulates an- 
tecedents. For present purposes, however, let us consider just these postulates 18 . 

The purpose of bringing conditional obligation in now, aside from the intrinsic 
virtues of such a notion, if any, is not so much to raise issues about deontic 
dilemmas, for these should play out the same in the dyadic context as in the 

18 Van Fraassen [36] proposed another fairly minimal axiom 

h 0{B/A) -> 0(A/\B/A) 

One might also consider a general axiom of reflexivity 0(A/A), which with condi- 
tional aggregation would render van Fraassen’s redundant. Van Fraassen’s own first 
proposal for a logic of conditional obligation with conflicts [37] p. 17 included (RCE), 
a rule corresponding to (RM) for inheritance in the consequent, 

CRM) If h B -s- C then b 0(B/A) 0{C/A) 

as well as the above, but neither (CN) nor (CP). Chellas [2] §10.2 proposed a system 
he called CD (not to be confused with van Fraassen’s CD of [36]) for a minimal 
conditional deontic logic. It is given by adding to (PC) just (RCE), the unrestricted 
inheritance rule (CRM), and a weaker version of (CP), namely, OA — > -iO(_L/A), 
where the O represents alethic possibility such as given by S5. Thus the language 
of CD requires alethic modalities; in their absence, this principle would have to be 
strengthened to (CP). Chellas prefers the weaker version in order to allow models 
in which 0(_L/_L) is true. In [14] and [15] I presented a conditional analog to the 
system P described above in Sect. 2.3; I called this DP. It contains (RCE), (RCM), 
(CN), (CP), and also a principle of transitivity for (weak) preference 

(A>BAB>C)^A>C 

where A> B = d f -<0(->A/AvB). This system DP corresponds to the dyadic deontic 
logic of van Fraassen of [36], his CD, and of David Lewis in [25] Ch. 6, there called 
VN, and in [26], much as the logic P stands to SDL. DP will accept conditional 
deontic dilemmas, but does not account for conditional versions of arguments like 
that of Smith’s service to his country. 
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monadic, and thus not require anything new, as rather to suggest that a move 
similar to that which let DPM accommodate deontic dilemmas can be applied 
to another problem that arises specifically in the context of dyadic deontic logic, 
and which is independent of questions of deontic dilemmas or normative conflict. 
This is a problem broached, but not settled, by Horty in a number of places, 
e.g., [19], [20], to question the treatment of conditional obligation within the 
framework of traditional modal or conditional logic, such as we see in standard 
dyadic deontic logics, like van Fraassen’s CD or their weaker counterparts like 
DP mentioned in footnote 18. 

In logics of conditional obligation, the principle of ‘strengthening the an- 
tecedent’ (SA) 

0(A/B) -»• O(AfBAC) 

is not valid. This is the virtue of these systems, in contrast to attempts to define 
conditional obligation in terms of a monadic ought-operator and ordinary con- 
ditional, e.g., as 0(A/B) = 0(A — > B) or A — > OB. Nevertheless, Horty argues, 
there seem to be cases where strengthening the antecedent seems appropriate, 
and by its wholesale rejection systems like CD or DP are unable to account 
for these cases. This is a lot like the situation with the argument about Smith’s 
service to his country, which challenged the wholesale rejection of Aggregation, 
though the form of the case is different. 

The example Horty uses to make this point draws on rules of etiquette, but it 
is easy to imagine counterparts in other normative domains. We are given these 
rules: 

i) You ought not to eat with your fingers — 0(~>F/T) 

ii) You ought to put your napkin on your lap — 0(N/T) 

iii) If you are served asparagus, you ought to eat it with your 
fingers — 0{F/ A) 

Here the third rule might be said to override the first, so that we should not be 
able to conditionalize (i) to A. That is, one should not be able to strengthen its 
antecedent to 

iv) If you are served asparagus, you ought not to eat with your 
fingers- 0(~<F/A) 

inferred from (i). And indeed in the usual logics one cannot. Horty’s concern, 
however, is with rule (ii). This does not seem overriden by (iii), and it seems 
plausible to infer from (ii) that 

v) If you are served asparagus, you ought to put your napkin 

on your lap - 0(N/A) 

Yet this inference is not valid the usual logics of conditional obligation. 

Thus the situation seems much like that that arose with respect to aggre- 
gation as discussed in Sect. 2.3. One wants to exclude some applications of the 
rule, but not all. I suggest a similar solution. One wants to block the rule in 
cases of conflict, as in the case of (i), but allow it when there is no conflict 
(ii). ‘Conflict’ here certainly means logical conflict, logical inconsistency, but 
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also, I suggest, deontic dilemma, impermissibility. Hence one might include this 
restricted principle of permitted strenghtlrening of the antecedent (PSA) 

PSA) b (0(B/A) AP(B/AAC)) -+0(B/AaC) 

in one’s logic of conditional obligation. 

This blocks the inference from (i) to (iv) in the presence of (iii) , for (iii) entails 
-^P(->F/A) (by definition of P(— /— )), and so the conjunct necessary for the 
antecedent of (PSA) cannot be included in the premise set without contradiction. 
On the other hand, we can suppose that P(N/A) is implicitly present, and with 
it (ii) yields (v) by (PSA). 

In this way, just as with the rule of permitted inheritance (RPM), a system 
of deontic logic within the traditional framework of modal or conditional logic 
is able to steer a middle course between accepting all inferences of the original 
pattern and accepting none. 

The principle (PSA) is interesting for it corresponds quite closely to a rule 
discussed in the literature of nonmonotonic, or defeasible, reasoning. This is the 
rule known [1] as ‘determinacy preservation’ (DP), 

DP) If A f- B and then AAC B 

where the sign ‘ |~’ represents a nonmonotonic inference relation, that B (nor- 
mally) follows from A. Although their interpretations are quite different, there 
is a strong formal analogy between conditional assertions A |~ B and assertions 
of (first-degree) conditional obligation 0(B/A). With that in mind, we can see 
that (DP) maps directly to (PSA) above. 

Given the other principles of a preferential nonmonotonic inference relation 
(DP) turns out to be equivalent to a principle of ‘rational transitivity’ (RT), 

RT) If A |~ B and B C and A -i C then A |~ C 

(Cf. [1].) This is quite a strong rule, and it, or rather its analog for conditional 
obligation 

b (0(B/A) A 0(C/B) A -iO(-iC/A)) -> 0{C/A) 

probably takes one farther than one would want to go for a logic of conditional 
obligation. (In a preference based semantics for the deontic logic it would require 
the preference relation between possible worlds be quasi-linear.) 

Horty’s problem can, however, be answered with a principle weaker than 
(PSA) or (DP). Consider this 

RSA) b (0(B/A) A P{C/A)) -> 0(B/A A C) 

In other words, one can strengthen an antecedent when the added condition, C , 
is permitted under the main condition, A. With this, and the implicit premise 
P(N/A) as above, then the inference from (ii) to (v) still goes through, even 
while the inference from (i) to (iv) is blocked. 

This rule (RSA) of ‘restricted strengthening the antecedent’, or ‘rational SA’, 
corresponds to the rule of ‘rational monotonicity’ (RatMono) in nonmonotonic 
logic, 
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RatMono) If A B and A \jC -■ C then A A C B 

This rule defines the class of preferential nonmonotonic inference relations that 
are called ‘rational’. Semantically it corresponds to the modularity of the prefer- 
ence ordering on models (equivalently, the transitivity of the complement of the 
converse of the strict ordering). Its deontic analog, (RSA) is already present in 
standard systems of dyadic deontic logic, and thus nothing new is needed to ac- 
commodate Horty’s concern. In a preference-based semantics for such a deontic 
logic its validity is guaranteed by the transitivity of the weak preference ordering 
of alternative worlds. With some other basic assumptions of dyadic deontic logic, 
it is equivalent to the principle of transitivity mentioned in footnote 18 19 . 

As noted above, this particular problem is independent of the question of 
deontic dilemmas and how a deontic logic should accommodate them. Indeed, 
the principle (RSA) is not contained in the minimal systems CDPM as initially 
set out, though it could be added. The purpose of these last remarks was to 
indicate that just as one might want to steer a middle ground between rejecting 
a rule altogether, like deontic (R.M) or (AND), and accepting it wholesale, and 
that one can do this by qualifying it through a clause relating to permission, so 
the same sort of maneuver will apply to this other kind of case. One wants to 
find a middle way between unrestricted strengthening of the antecedent and none 
at all, and that too can be done by paying attention to permissions, or in the 
framework of nonmonotonic inference relations, by bringing non-Horn premises 
into the rules. 



5 Conclusion 

Most of the discussion of this paper is motivated by problems Horty presented for 
deontic logic that wants to allow for the possibility of deontic dilemmas. While it 
is easy to design a logic that accepts that possibility while keeping to a classical 
base for deontic logic, e.g., the logic P of Sect. 2.3, it is not so easy to design 
a logic that also accounts for the further inferences that Horty puts forward as 
unproblematic. In Sect. 2.4 I looked at a couple of proposals, which, however, 
turn out to be inadequate. In Sect. 3 I presented a different approach that fares 
better, and so I recommend it as a basic monadic deontic logic to accomplish both 
purposes, to accommodate deontic dilemmas while also accounting for Horty’s 
examples. In Sect. 4, I sketched how this approach can be extended to the logic 
of conditional obligation, and suggest how similar maneuvers can also respond 

19 Delgrande [5] argues that a rule like the present (RatMono) is too strong; it resolves 
Horty’s original problem, but then lets in inferences that should not be accepted. 
Analogous cases would confront the standard systems of dyadic deontic logic, such as 
van Fraassen’s CD of [36], which I call SDDL, [14]. Delgrande’s cases are blocked, 
however, in the weaker dyadic logic DP of [14], which corresponds to the weak 
monadic logic P described in Sect. 2.3 above, and likewise in its nonmonotonic 
counterpart. That is because this system lacks (conditional) aggregation (CAND), 
and also principles corresponding to CUT and OR for the antecedent. 
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to other problems Horty has raised for this way of doing deontic logic, or the 
logic of nonmonotonic reasoning. 

Nevertheless, there is a fundamental difference between the way I have pro- 
posed looking at these kinds of situations and the way Horty would look at them. 
Horty sees deontic logic belonging to the domain of nonmonotonic logic, that is, 
a logic in which an argument with premises r and conclusion A might be valid 
even while an argument with premises r' and conclusion A is not valid, even 
though r C r' . In classical logic validity is never lost with the addition of new 
premises. The logics DPM, and CDPM, and their enrichments with principles 
like (RSA) described above are all classical in this respect. 

The difference in approach can be seen most clearly with the example con- 
cerning strengthening the antecedent and how to eat asparagus, though much 
the same could be said with regard to the example of Smith’s service to his coun- 
try. With F for ‘you eat with your fingers’ and A for ‘you are eating asparagus’, 
the nonmonotonic approach would regard the argument 

I) a) 0(~>F/T) 

c) 0(->F/A) 

to be valid, but the argument 

II) a) 0(-iF/ T) 
b) 0(F/A) 

,-.c) O^F/A) 

not to be valid. This illustrates the nonmonotonicity of the consequence relation. 
(Cf. [20], p. 35.) 

By contrast, the approach I proposed would say that, strictly speaking, ar- 
gument (I) is not valid. If it appears to be, that is because there is an additional 
premise implicit in the context, and that (I) should be considered entlrymematic 
for 

I) ' a) 0(->F/T) 

d) P^F/A) 

.-. c) OirF/A) 

Then (c) follows from (a) and (d) by the rule (RSA). And if (II) seems not to 
be valid, that is because with the addition of premise (b) the implicit premise 
(d) is withdrawn, in which case (RSA) does not apply. (If (d) is maintained, so 
that the argument is really 

II) ' a) 0(->F/T) 

b) 0{F/A) 
d) P^F/A) 

,-.c) O^F/A) 

then one is confronted with an inconsistent premise set since (d) is equivalent to 
(d') -iO(F/A), which contradicts the new premise (b). Although (II)' is classi- 
cally valid, it should be rejected for that inconsistency.) 

Similarly, in the example concerning Smith’s service, from the nonmonotonic 
point of view, the argument 
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III) a) 0(F V S) 
b) 0(->F) 

.*. c) OS 

is regarded to be valid as it stands, whereas DPM would say that it is, strictly 
speaking, not valid, but it might appear to be because of a tacit premise, and 
that what is really valid is the argument 

III)' a) 0(F V S) 
b) 0(->F) 
d) P(->F A S) 

.*. c) OS 

where the conclusion (c) follows from (a), (b) and (d) by (RPM) and (AND), or 
(PAND) as described at the end of Sect. 3. 

Much like the free logician described in Sect. 3, I take it that arguments like 
(I) and (III), insofar as they are to be considered valid, rest on presuppositions, 
tacit premises that are made explicit in (I)' and (III)' . Because the latter forms 
are valid in DPM, the apparent validity of (I) and (III) is explained. At the 
same time, the non- validity of argument (II) is also explained since the additional 
premise requires cancelling the presuppositions of the first argument. 

Thus the difference between Horty’s approach and what I have recommended 
concerns what concept of validity is being ascribed when evaluating arguments, 
and also the identification of the precise argument that is evaluated (does it 
include the tacit premise, or not?). It is plausible that both approaches have their 
proper roles to play in analyzing normative discourse. At any rate, the issues 
raised by the contrast go far beyond the purposes of the present discussion, and 
do not need to be decided here. 



Appendix 

In this Appendix I dress the logics DPM and CDPM in more formal clothing, 
and demonstrate that they are sound and complete with respect to an appropri- 
ate semantics. Because these are non-normal, but still classical modal logics the 
neighborhood semantics familiar from Segerberg [34] or Chellas [2] Clr. 7-9 is 
readily adapted to them. Nevertheless, the completeness theorems given below 
are a bit tricky, and so, perhaps, more interesting. In the course of completing 
these proofs I also establish that these logics have the finite model property and 
hence, because they are finitely axiomatizable, they are decidable. 

Let us take up the monadic logics DPM first; results for CDPM will then 
follow quickly by similar procedures. The language, C, for DPM is a proposi- 
tional language adequate for classical propositional logic plus the monadic de- 
ontic operator O such that OA is well-formed whenever A is. ‘A’, ‘ B\ ‘C\ etc. 
are variables for arbitrary formulas of C. A — > B is understood to be equivalent 
to -i A V B and to ->{A A ~>B). A <-> B is (A — » B) A (B — > A). As usual, PA 
abbreviates - 1 O- 1 A. T is any classical tautology and _L is -iT. 




A Proposal for Dealing with Deontic Dilemmas 



99 



DPM.l is the least set of formulas containing all classical tautologies of formulas 
of £, plus all instances of 

N) OT 

AND) (OA A OB) 0(A A B) 

and closed under the rules 

MP) if b A — > B and b A then b B 

RE) if b A o B then b OA o OB 

RPM) if b A ^ B then b PA -> (OA — »■ OB) 

where b indicates membership in DPM.l. 

DPM.2 is the least the set of formulas containing all classical tautologies of 
formulas of £, plus (N) as above and also all instances of 

P) -OT 

PAND) (OA A OB A P(A A B)) 0(A A B) 

and closed under the rules (MP), (RE) and (RPM) (with b for membership in 
DMP.2; henceforth, we shall take it to be clear what b signifies in context). 

For the semantics for these logics, formulas of C are interpreted with respect 
to neighborhood frames. The key idea here is to take obligatoriness, or normative 
requirement, to be a property or attribute of propositions. A formula OA is 
then true just in case the proposition expressed by A has this property. More 
precisely, consider a proposition to be a set of possible worlds, and accordingly 
the proposition expressed by A to be the set of worlds at which A is true; 
designate that set |A|. Consider a property of such propositions extensionally, as 
a set of propositions, and thus a set of sets of possible worlds. Each possible world 
a has associated with it a set O a of propositions; these are the propositions that 
are obligatory (from the point of view of a). If |A| is the proposition expressed 
by A (on a model), i.e., the set of possible worlds where A is true (on the model), 
then OA is true (at a on the model) just in case |A| is a member of O a - 

More formally, define a neighborhood frame, F, to be a pair (IT, O) in which 
IT is a non-empty set of points, e.g., possible worlds, and O is a function assigning 
every a € IT a set, O a , of subsets of IT; i.e., O a C pIT. A model, M, is a pair 
(F,v) where F is a neighborhood frame (IT, O), and v is a function assigning 
every atomic formula p of C a subset of IT, i.e., v(p) C IT. A satisfaction relation 
|= is defined as usual, so that for any model M = ( F , v) on a frame F = (IT, O), 
for any a £ IT, 

T p) M,a\= p iff a G v(p) 

T — ') M, a |= —>A iff M, a A 

TA) M, a |= A A B iff M, a\= A and M, a f= B 

TV) M, a \= A V B iff M, a \= A or M, a \= B 

and in particular 

TO) M,a\= OA iff \A\ M e O a 
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where \A\m = {a £ W : M,a \= A}. \A\m is the proposition expressed by A on 
the model M. 

It is helpful to note 

Proposition 1. For any model, M, (i) \AAB\m = M n\B\ m; (a) \avb\m = 
\A\ m U \B\ m ; (in) \->A\ M = -\A\ M ; (iv) |T| M = W; and (v) |_L| M = 0- 

where — A is the complement of A with respect to W, i.e., —X = W — X 
= {a £ W : a ^ X}. Generally speaking, the relativization to W should be 
understood in context; in later arguments when two models, one a submodel 
of the other, are being discussed together, it will be necessary to be careful to 
distinguish one complement from the other. 

As usual, a model M satisfies A, or A holds on M — M \= A — iff M, a \= A 
for every a £ W when M = (F,v) and F = ( W,0 ). A is valid on a frame F 
— F \= A — iff M |= A for every model M = ( F , v) on F, and A is valid in 
a class of neighborhood frames F F \= A — iff F f= A for every F £ F. 
A set of formulas S is sound with respect to a class of frames F iff F |= A for 
every A £ S. S is complete with respect to F iff for every A that F |= A, A £ S. 
Similarly, S is sound with respect to a class of models, J4, iff M |= A for every 
model M £ XI, and S is complete with respect to XI iff for every A such that 
for all M £ XI, M |= A, A £ S. The contrast between frame-completeness and 
model-completeness will be useful below. 

For later reference, it is also useful to note 

Proposition 2. For any model, M, (i) M \= A —> B iff \A\m C \B\m, and (ii) 
M \= A B iff \A\ m = \B\ m . 

The set of formulas that comprise DPM.l is both sound and complete with 
respect to the class of neighborhood frames F = ( W , O) that meet the following 
three conditions: For all X, Y C W and all a £ W, 

a) W £ O a 

b) If A G O a and Y £ O a then A n Y £ O a 

c) IfACT and X £ O a and —A i O a then Y £ O a 

Condition (a) validates axiom (N), condition (b) validates the aggregation axiom 
(AND) and condition (c) validates (RPM). ((RE), and later (RCE) and (CRE), 
come for free.) 

The set of formulas that comprise DPM.2 is both sound and complete with 
respect to the class of neighborhood frames F = (W,0) that meet the conditions 
(a) and (c) above for all A, Y C W and all a £ W, but with condition (b) 
modified to 

by IfAe0 a and Y £ O a and -(A n Y) </ O a then A n Y £ O a 
and also the additional condition 

d) 0 i O a 

(by validates the weakened aggregation principle (PAND) while (d) validates 
axiom (P). 
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Theorem 1. (i) DPM.l is sound with respect to the class of frames that satisfy 
conditions (a)-(c); (ii) DPM.2 is sound with respect to the class of frames that 
satisfy conditions (a), (b)' , (c) and (d). 

Proof. As usual this is simply a matter of showing that the axioms, (N) and 
(AND) of DPM.l and (N), (PAND) and (P) of DPM.2, are valid in the re- 
spective classes of frames and that the rules preserve validity. These are easy 
enough to leave to the reader, but here is the argument for the rule (RPM) 
since this is new to the literature. With T a class of frames that satisfies con- 
dition (c), suppose that F |= A — > B, and show that F {= PA — > ( OA —>■ OB). 
For that suppose a frame F = (IT O) G T and a model M = ( F , v) and an 
a £ IT such that M, a |= PA and M, a \= OA. By Proposition 2.i, \ A\m C \B\m- 
Since M,a f= PA, M, a O^A, so that |-M| m ^ O a . By Proposition l.iii, 
— \A\m O a - Since M,a (= OA , \A\m G O a - Hence, since F satisfies condition 
(c), \B\m G O a , and therefore M,a |= OB, as required. (The argument for the 
validity of permitted aggregation (PAND), given condition (b)', is similar.) □ 

In light of later arguments, it is useful to mention this immediate corollary 
to Theorem 1, 

Corollary 1. DPM is sound with respect to the class of finite frames that sat- 
isfy conditions (a), (b), (c), or (a), (b)' , (c), (d), as appropriate. 

Before taking up the question of completeness, let us first fulfill a promise 
made in the main text, to demonstrate that neither (D) nor deontic explosion, 
in its various forms, is derivable in DPM. That (D) is not, is manifest from 
the fact that DPM is a subsystem of the normal modal logic K, and (D) is 
well known not to be derivable in K. Not only is deontic explosion in the form 
(DEX), {OA A O-i A) — > OB, not derivable in DPM, but neither is (DEX-2), 
{OAaO~<A) — > { PB — »• OB), which undermined the logic PA described in Sect. 
2.4.3, nor is (DEX-3), {OCAPC) — > {{OAaO~>A) — > {PB — > OB)), which would 
vitiate DPM enriched with an unrestricted (K) principle, discussed in Sect. 3. 
To prove this, here is a model for each version of DPM that will falsify the 
latter, and so the others, including also (DEX-1). By Soundness of the systems, 
Theorem 1, it follows that these schemas are not derivable in DPM. 

For that model for DPM.l, let F = (IT, O) with IT = {a,b,c}, and O a = 
{IT, 0, {a, &}}, and Ob = O c = {IT, 0}. Given F, let M = {F,v), with v{p) = 
IT, v{q) = {a, b} and v{r) = {a}, {v for any other atomic formula could be 
anything.) With these specifications, it is not difficult to show that F satisfies 
the conditions (a), (b) and (c) for a frame for DPM.l, and also that M, a (= Op, 
M,a\= 0~<p, M, a (= Oq, M,a (= Pq, M,a\= Pr and M, a \f= Or. (Verification 
may be left to the reader.) This suffices to falsify this instance of (DEX-3), 
{Oq A Pq) — > {{Op A 0~>p) — > {Pr — > Or)), as promised. 

For DPM.2 we require a model on a frame that meets condition (d) and (b)' 
rather than (b), as well as (a) and (c). For this take IT = {a, b, c}, as before, but 
let O a = {W, {a},{b,c}} (and Ob = O c = {IT}). It is then easy to show (and 
so left to the reader) that F = (IT, O) meets the requisite conditions. For M on 
F, let v{p) = {a}, v{q) = IT and v(r) = {b}. This too will falsify the instance of 
(DEX-3) (verification left to the reader). 
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Turning now to the completeness of the logics DPM, as is so often the case, 
this is more difficult to establish than soundness, and indeed, for these it is 
more complicated than one might have predicted at first. Let us begin with the 
familiar. Define a canonical model M c = ( F c ,v c ) on a frame F c = (W c ,O c ), 
as follows: W c is the set of all maximal consistent extensions of DPM (either 
version as appropriate). Let [A] = {a £ W c : A £ a}. For each a £ W c , let 

O c a = {X C W c : 3 A(X = [A] and OA £ a)} 

O c assigns O ° to a. Let v c be such that for every atomic formula p 

v c (p) = {a £ W c : p £ a} 

As a syntactical counterpart to Proposition 1, it is helpful to note 

Proposition 3. For any A andB, (i) [ AAB ] = [A]n[.B]; (ii) [AvB\ = [A]U[.B]; 
(in) bA] = - [A] ; (iv) [T] = W c ; (v) [_L] = 0. 

These may be left to the reader to verify. Also, corresponding to Proposition 2, 

Proposition 4. For any A and B, (i) [A] C [B] iff\- A — >• B, and (ii) [A] = [B] 
iffhA^B. 

Proof. For (i), suppose [A] C [B] but K A-> B. Then {A, ~^B} is consistent, 
and so has a maximal consistent extension, b. A £ b so b £ [A]. Hence b £ [B], 
which is to say B £ b, contrary to the consistency of b since ->B £ b. Therefore, 
b A — > B. Further, if b A — > B, then since maximal consistent extensions are 
closed under provable implications, it is automatic that for any a £ [A], a £ [B\, 
or [A] C [B\. Part (ii) follows immediately from (i). □ 

Lemma 1. For all A and all a £ W c , M c ,a \= A iff A £ a (or, \A\ M c = [A])- 

Proof. As usual, by induction on A. This is immediate from the definition of v c 
when A = p, and it is routine when A = B A C, A = B M C or A = ~^B. We 
consider the case when A = OB under the assumption that \B\m c = [B\. (a) 
Suppose OB £ a. By the inductive hypothesis \B\ M c = [B], hence there is a C 
such that \B\m<= = [C\ and OC £ a. By definition \B\m <= £ O c a , which suffices 
immediately for M c ,a b OB. (b) Suppose M c ,a b OB, so that \B\m ■= £ O 
Then [B\ £ 0 ( a , by the inductive hypothesis. Consequently, there is a C such 
that [B] = [C] and OC £ a. For such a C, since [C] = [B], b C -O- B, by 
Proposition 4.ii. Hence, b OC —> OB by (RE), so OB £ a, as required. □ 

Ordinarily that would suffice to establish completeness for the system, since 
if b A, { _| A} is consistent, and so has a maximal consistent extension b. By 
Lemma 1, M c , b \= ~>A, and so M c , b b A, and then M c b A. Hence A could not 
be valid. Thus, by contraposition, if A were valid, it would have to be provable 
in DPM. What is missing, however, is that M c is a model on a frame F c that 
satisfies all of conditions (a)-(c) (for DMP.l) or (a), (b)', (c), (d) (for DMP.2). 
And we do not have that. Condition (c) fails, as does (b)'. 
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To see how (c) fails, consider an X,Y C W c such that X CY and X £ O c a 
and —X £ O c a . Hence, there is a C such that X = [C] and OC £ a, and also, with 
some manipulation, 0~>C (j a, whence, by maximality, —>0—>C £ a or PC £ a. 
If there were a formula D such that Y = [D], then (c) would follow, since then 
[C] C [D], so b C D, by Proposition 4, and so b PC -£ (OC — > OD ), by 
(RPM), and so OD £ a , by (MP) twice, which would suffice for Y £ O But 
there is no guarantee that there will be any such D. If we were to modify the 
definition of O c a , e.g., to have, for example, 

O c a = {X CW c : 3 A([A] C X and OA £ a)} 

or equivalently if we take the supplementation of F c to be the canonical frame, 
then (c) would be satisfied, indeed, F c would be a frame for full inheritance 
(RM), but then the key Lemma 1 would be lost. A similar problem infects (b)' 
for DPM.2. Hence we must find another model that will do the job of falsifying 
any non-theorem while being based on a frame in the class F of frames that 
meet the requisite conditions. 

Nevertheless, this stumbling block does suggest that from Lemma 1 we can 
conclude at least the model-completeness of DPM. From that, as we shall see, 
it will be possible to establish full-blooded frame-completeness. 

For model-completeness, consider any model M = ( F , v ) on a neighborhood 
frame F = (W,0). Let Em be the set of expressible propositions on M. That is, 

Em = {XCW: 3B(X = \B\ M )} 

We can then modify the frame conditions above to form conditions on models, 
by restricting X and Y to expressible propositions. Thus 

a) m W £ O a 

b) m For all X, Y £ £ M and a £ W, if X £ O a and Y £ O a 

then Ink £ O a 

c) m For all X, Y £ E M and a £ W, if X C Y and X £ O a 

and —X^O a then Y £ O a 

b) ,m For all X,Y £ £ m and a £ W, if X £ O a and Y £ O a 
and -(X n Y) <£ O a then X (1 Y £ O a 

d) m 0 i O a 

Theorem 2. (i) DPM.l is sound and complete with respect to the class of 
models that satisfy conditions (a) m , (b) m , and (c) m ; (ii) DMP.2 is sound and 
complete with respect to the class of models that satisfy (a) m , (b/ m , (c) m and 
(d) m . 

Proof. As usual, soundness is routine; the argument for Theorem 1 applies mu- 
tatis mutandis. For completeness, given Lemma 1, it suffices to establish that 
M c as specified above meets the requisite conditions. 

For (a) m , since W c = [T] (Proposition 3.iv) and since h O T (axiom (N)), 
so that OT £ a, it follows that there is a B such that W c = [B\ and OB £ a, 
which yields W c £ O c a . 
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For (b) m , consider any X, Y £ £m c and a £ W c , and suppose X £ 0° 
and Y £ 0°. Hence there are B and C such that X = \B\m* and OB £ a 
and Y = |C|m<= and OC £ a. By Lemma 1, \B\m <= = [B] and \C\m c = [C]- 
Since (OB A OC) — > 0(B A C) is a theorem of DMP.l, 0(B A C) £ a. Hence 
[B AC\ £ 0%. By Proposition 3.i, and Lemma 1, [B AC\ = [B] (~l [C\ = \B\m^ fl 
\C\m° = X C\Y. Hence X fl Y £ O as required. 

For (c) m , consider any X,Y £ £m<= and a £ W c , and suppose X C Y and 
X £ O a and — X £ O)). Hence, there is a B and a C such that X = \B\m <= 
and Y = |C|m c and there is a D such that X = [D] and OD £ a. By Lemma 
1, \B\ M c = [B] = [D], hence OB £ O c a by (RE) and Proposition 4.ii. Since 
-\B\ M c i O c a , for all D such that -X = '[£>], OD £ O c a . -X = -\B\ M ° = 
\~>B\mc, by Proposition l.iii, = [->£?], by Lemma 1. Hence 0~>B ^ a, and by 
maximality, ->0~>B £ a, or PB £ a. Since X C Y, \B\m° Q |C|m°, so by 
Lemma 1, [B\ C [C], whence by Proposition 4.i, h B — > C. Therefore, by (RPM), 
b PB — > (OB — > OC). Hence, by (MP) twice, OC £ a. That suffices for Y £ O)), 
as required for this case. 

For (b) ,m , consider any X,Y £ £m°, and suppose X £ O a and Y £ O a 
and -(Inh) ^ O a , and show that X fl Y £ O a - Given that X = \B\m<= and 
Y = \C\m c , for some B and C, so that X = [B] and Y = [G], by Lemma 1, 
then —(X flF) = [~'(B A C)\, by Proposition 3. Since [B\ £ O a and [C] £ O a , 
there are D and E such that [B\ = [D] and [C] = [E] and OD £ a and OE £ a. 
\- B ■£> D and h C £> E, by Proposition 4. Hence OD — > OB and OE — > OC, by 
(RE), so that OB £ a and OC £ a. Further, 0^(B AC)^a, for if it were, then 
— (X n r) £ O a , contrary to the supposition. Therefore, ->0~>(B A C) £ a, or 
P(BAC) £ a. By the postulate (PAND) of DMP.2, it follows that O(BAC) £ a, 
which suffices for X n Y £ O a , as required. 

For (d) m , suppose 0 £ O a - Then there is a formula B such that 0 = [B\ 
and OB £ a. 0 = [_L] (Proposition 3.v). Hence [_L] = [B], and so h 1 f> B, by 
Proposition 4.ii.. Therefore, OA. £ a by (RE) . But-'OT is a theorem of DPM.2, 
and so ->0-L £ a, contrary to the consistency of a. Thus, 0 ^ O a . 

This suffices for the theorem since if A is a formula not provable in DPM, 
then { _ 'A} is consistent and so has a maximal consistent extension a £ W c . By 
Lemma 1, M c , a |= -■ A, and so M c , a A, and thus M c \£A. Since M c satisfies 
the conditions (a) m -(d) m , there is thus a model meeting these conditions on 
which A does not hold. Hence, by contraposition, if A is a formula that holds of 
every model that meets these conditions, it must be provable in DPM. □ 

We can extract frame-completeness from Theorem 2 if, for any model M 
meeting the conditions (a) m , (b) m , (c) m for DPM.l or (a) m , (b) /m , (c) m , (d) m 
for DPM.2 that falsifies a non-theorem A of the system, there is a corresponding 
model on a frame that meets the original frame conditions (a), (b), (c), or (a), 
(h)', (c), (d), that also falsifies A. We obtain this by taking a filtration of M, 
and applying a little more manipulation. This will yield a model on a frame in 
which every proposition is expressible, and so the satisfaction of conditions (a) m , 
(b) m , (c) m ((a) m , (b) ,m , (c) m , (d) m ) will imply the satisfaction of (a), (b), (c) 
((a), (by, (c), (d)). The resulting model will be a model on a finite frame, and 
so as a spin-off benefit, we shall establish that each version of DPM is complete 
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with respect to the class of finite frames, and so has the finite model property, 
from which it follows that DPM is decidable since it is finitely axiomatizable. 

Given a model M = (F, v) on a frame F = (W, O) with M satisfying con- 
ditions (a) m , (b) m , (c) m , or (a) m , (b )' m , (c) m , (d) m ), as above, construct an 
alternative model M* = ( F*,v *) as follows: Let ip be a finite set of formulas 
closed under subformulas, i.e., if A £ ip and B is a subformula of A then B £ ip. 
Let Pi/, be a particular atomic formula in ip and let T = and _L = -iT. 

Let F be the closure of ip under truth- functions, i.e., F is the smallest set of 
formulas such that ip C F and if A, B £ F, then A/\B£F,A\JB£F and 
-iA £ F. We note that T £ F and _L £ F, and that F itself is closed under 
subformulas. 

Given M and such a ip, define an equivalence relation =,/, on W such that, 
for all a, b £ W, 

a b iff VB( if B £ ip then (M, a |= B iff M, b |= B)) 

This generalizes to F, thus 

Proposition 5. For all a,b £ W, if a =,/. b, then for all B £ F, M,a\= B iff 
M,b\= B. 

Proof. Suppose a =,/, b and B £ F. Proof is by induction on B. If B is atomic 
or of the form OC, then B £ ip, and so M, a \= B iff M, b \= B follows from the 
definition of =,/,. If5 = CAPorCVDorB = ->C, for some C and D, then 
the result follows directly from the inductive hypothesis. □ 

The relation partitions W into finitely many equivalence classes [a] for 
a£ W, 

[a] = {b £ W : b a} 

This is familiar from standard modal logic. Now, however, we do something a 
little different; we make what might be called a ‘thin’ filtration. This is required 
in order to assure that the frame F* that is derived from F will meet condition 
(c), and also (b)' as appropriate. 

For each of the equivalence classes [a], take exactly one member; call it a*, 
(a* need not be a itself.) Let W* be the set of all such selected a*. Then the 
following facts obtain. 

Proposition 6. (i) W* C W; (ii) W* is finite; (Hi) for all b £ W there is an 
a* £ W* such that b = ^ a* ; (iv) for all a*,b* £ W* , if a* b* then it is not the 
case that a* b*. 

These all follow directly from the definitions (and the finitude of ip). 

For some convenient notation, for every X C W , let X f = X D W*. Also 
we continue to write \A\m for {b £ W : M, b \= A}, but since M is given by 
the context of this discussion, let us drop the subscript, except when it is really 
required for disambiguation (e.g., in the proof of Lemma 6 below to distinguish 

\A\ m from \A\ m *). 
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Given M = ( F , v) with F = ( W, O ), we can now specify the alternative model 
M* = (F*, v*). Let F* = (W*,0*) with W* as specified {W* = W J,), and O* 
such that for all a* G W* and all X* C W * , 

X* G £>*, iff 3 B{B G F and X* = \B\ | and \B\ G 0 a *) 

And for all atomic formulas p, 



v*(p) =v(j>) l 

The principle task now is to show (1) that if M satisfies conditions (a) m , 

(b) m , (c) m , or (a) m , (b ) ,m , (c) m , (d) m , as appropriate, then F* satisfies (a), (b), 

(c) , or (a), (by, (c), (d), and (2) that M and M* are equivalent modulo ip. To 
this end some preliminary lemmas are required. 

Lemma 2. For all a* G W* , there is a formula B gF such that \B\ j. = {«*}■ 

Proof. This is established by a sort of diagonal argument 20 . Note first that for 
all a*,b* G W*, if a* y b* then there is a formula C such that C G F and 
a* G \C\ and b* £ \C\. For suppose otherwise. Suppose a* y b* but for every 
C G F if a* G \C\ then b* G \C\. Then a* b * , for consider any D G ip, hence 
D G F. If M,a* |= D , then a* G \D\, so by the supposition b* G \D\, and thus 
M,b* |= D. Suppose then that M, If |= D, i.e., b* G \D\, but that it is not the 
case that M,a* |= D. Then M,a* (= ~<D and a G |->.D|. ~<D G F: so, by the 
supposition, b* G |— >Z)|, or M, b* (= -<D. That means M, b* \f=D, a contradiction. 
Hence, if M, b* f= D , then M, a* |= D , and so M, a* (= D iff M, b* (= D , which 
suffices for a* =,/, b* . But if a* y b* then it is not the case that a* =,/, b*, by 
Proposition 6.iv, a contradiction. Therefore, it must be the case that if a* y b*, 
there is a C £F such that a* G \C\ and b* £ \C\. For each b* such that b* y a*, 
select one such formula, and call it Cb * . Let a be the set of all such formulas 
Cb * • a is finite since W* is finite. Let B a » be a conjunction of all the members of 
a. B a * G F since each conjunct Cb * G F and F is closed under truth- functions. 
We now show that \B a * \ j. = {a*}. 

(i) Suppose x G \B a *\ J.. So x G \B a *\ and x G W*. Suppose a i / a*. Then 
there is a formula C x G a such that a* G \C X \ and x ^ \C X \. Because B a . is a 
conjunction of all members of a, b B a » — > C x . Hence, by soundness, Theorem 
1, M \= B a . — > C x , and so \B a * | C \C X \, by Proposition 2.i. Since x G \B a * |, 
x G \C X \, a contradiction. Therefore, if x G \B a -\, x = a* and so x G {a*}. Thus, 
\B a * \ 4 C {a*}. 

(ii) Suppose x G {a*}, i.e., x = a*. Thus x G W*. For all D G a, x G \D\. 

Hence if a = {D i, . . . , D n }, M,x\= D\ and . . . and M, x |= D n . Consequently, 
M,x (= Di A • • • A D n . But D\ A • • • A D n = B a » , so that M,x \= B a . . That is 
to say, x G \B a * |, and therefore x G \B a * \ j.. Thus, {a*} C \B a *\ j.. Therefore, by 
(i) and (ii) together, \B a * \ j. = {a*}, as required for the lemma. □ 

Lemma 3. For all X* C W* . there is a formula B such that B G F and 
X* = \B\ i. 

20 This argument draws from Hughes and Cresswell [22], p. 166, which draws in turn 
from Segerberg [34], pp. 31-33. 
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Proof. Suppose X* C W*. X* is finite, because W* is. Let X* = {a^, . . . , a*}. 
For every a* £ X* there is a formula B such that B £ F and | B a * | = {a*}, 
Lemma 2. For each such a* £ X*, select one such formula, and call it B a *. Let 
B y* = B a * V • • • V B a * . Bx * £ F since each disjunction is in F. We show that 
X* = \B x l\ 

(i) Suppose x £ X*. Then x £ W*. x = a* for some 1 < i < n. A* £ \B a * |, 
by specification, so 1 £ |F a *|, which is to say, M, x (= B a *. But then M,x |= 
B a * V • • • V F a . , i.e., M, x \= B x *• Thus x £ |Fx*|, and so 1 £ |Fx*| H W*, 
which is to say a: £ |F,y* I 4- Hence, X* C \B X * | 4- 

(ii) Suppose x £ \B X * \ 4, i.e., x £ \B X *\ C\W*. So a: £ W*, and M,x |= B x *, 

i.e., M,x \= B a * V • • • V F a . Hence, M,x\= B a * or . . . or M, x (= F a . . Suppose 
M, x |= F a *. Then a; £ |F a *|, and since \B a *\ = {a*}, by specihcation, x = a*. 
Since A* £ X*, x £ X*. Hence, |Fx*| 4 Q X*. Putting (i) and (ii) together, 
X* = \B X * | 4, as required. □ 

Lemma 4. For all B,C £ If - , (i) if \B\ 4 C |Cj 4. then \B\ C \C\; (ii) if 
\B\ 4 = |Cj 4, then \B\ = \C\. 

Proof. For (i), suppose some B, C £ P such that \B\ 4 C \C\ 4, and consider any 
b £ \B\. b £ W. Hence, there is an a* £ W* such that b =,/, a*, by Proposition 
6 .iii. Since M, b \= B, and B £ M, a* f= F, by Proposition 5, so a* £ |F|, 

whence a* £ \B\ 4- So, a* £ \C\ 4 and then a* £ |C|, or M,a* |= C. Since 
C £ P and b a*, M,b (= C, by Proposition 5. Thus, b £ |C|, as required for 
|F| C |C|. For (ii), the argument is just the same. □ 

We are now in a position to establish that, given a model M = (F, v) meeting 
model conditions (a) m , (b) m , (c) m , or (a) m , (b) ,m , (c) m , (d) m , as appropriate, 
then the derived frame F* meets the corresponding frame conditions. 

Lemma 5. (i) If M = (F,v) satisfies conditions (a) m , (b) m , (c) m , then F* 
satisfies (a), (b), (c), and (ii) if M satisfies (a) m , (b) ,m , (c) m , (d) m , then F* 
satisfies (a), (b/ , (c), (d). 

Proof. We consider the two parts together. Suppose M meets the described 
model conditions, as appropriate. 

For (a), since M meets (a) m , W £ O a *. W = |T|, so |T| £ O a * ■ T £ F. 
W* = | T | fl W* = | T | 4 . Hence there is a F £ F such that W* = |F| 4 and 
|F| £ O a *. That suffices for W* £ Of, , as required for F* to meet condition (a). 

For (b), consider some X, Y C W* and a* £ W* such that X £ O*, and 
Y £ O*, and show that X fl Y £ O*, . By hypothesis, there are F and C such 
that F £ F and X = \B\ 4 and |F| £ O a * and C £ F and Y = \C\ 4 and 
|Cj £ O a *. FAC £ F since F is closed under truth- functions. Because M 
meets condition (b) m , |F|n|C| £ O a , ; hence, |FAC| £ O a *, by Proposition l.i. 

xny = |F| 4 n|C| 4 = (iFinw^jndClnw*) = (|F|n|C|)nw* = (|F|n|C|) 4 

= |FAC| 4 (the last by Proposition l.i again). Since |FAC| £ O a *, XflF £ Of , , 
as required. 

For (c), consider X, Y C W* and a* £ W * , and suppose that X C Y 
and X £ O*, and —X ^ Of ,, where — is complementation with respect to 
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W * , that is, suppose W* — A ^ O*,. We show that Y £ O*,. By Lemma 3, 
there are formulas B and C such that B £ and X = \B\ and C £ and 
Y = \C\ f. Hence \B\ 4_ C \C\ 4- Since \B\ 4 £ O*,, there is a I? £ if - such that 
\B\ 4 . = |D| 4 and \D\ £ O a *. By Lemma 4, \B\ = \D\\ hence \B\ £ 0 a *. Since 
\B\ 4- C jci 4 ., |.B| C |C|, also by Lemma 4. We show that |C| £ O a *. For this, 
given that |J3| C \C\ and \B\ £ O a * , it will suffice that W — \B\ £ O a * , since M 
satisfies condition (c) m , by hypothesis. Suppose, for reductio, that W— \B\ £ O a *. 
W — \B\ — |— i.B|, by Proposition l.iii. Also ->B £ 'P, since P is closed under truth- 
functions. Consider W* — \B\ 4- This = \~<B\ 4 .. For suppose a b £ W* — \B\ 4- 
Thus, b £ W* but b £ \B\ 4, i.e., b ^ W*D|B|. Thus b £ \B\, and so b £ by 
Proposition l.iii. So, b £ W* (~1 which is to say b £ |->H| 4-, as required for 
W* — |H| 4- Q |-i£?| 4- For the converse, suppose b £ \~<B | 4 ., so that b £ W* and 
b £ Hence b \B\. Hence, b ^ W* fl \B\, i.e., b £ \B\ 4- So, b £ W* — \B\ 4 ., 
as required for \~<B\ C W* — \B\ 4- Since W* — |£?| 4 = I -1 -®! 4-) and si nce 
-<B £ P, and since W — \B\ £ O a », it follows that W* — \B\ 4 £ O*.. Hence 
W* — X £ O*,, in contradiction to the opening supposition. As noted, that 
suffices for |C| £ O a *, which suffices for \C\ 4- £ O*., i.e., Y £ O*,, as required 
for condition (c). 

For (b)', when M satisfies (b) ,m , the argument is similar. Consider A, A C 
W* and a* £ W* , and suppose X £ 0* a , and Y £ 0* a , and -(InF)^ O*,, 
where, as with (c), — represents complementation with respect to W* . Thus 
there are B and C such that B £ P and X = |2?| 4- and |B| £ O a » and C £ P 
and Y = \C\ and |C| £ O a - ■ B A C £ P since P is closed under truth- 
functions. As with (b), X CiY = |B| 4- n \C\ 4- = (|J3| fl W*) fl (|C| fl W*) 
= (\B\ n IC'D nr = (|H| n |C|) 4 = \B A C| 4 . We show that \B AC\ £ O a ., 
which will suffice then for X fl Y £ O*. . Since — (X fl Y ) ^ O *, , for every D £ P 
if — (An A) = \D\ 4 then |Z?| £ O a *. We show that — (JflF) = \~>{B AC)| 4- (i) 
Suppose x £ — (XnF), i.e., x £ IA* — (AnA). So, x £ W* and x ^ An Y. Thus, 
x £ \B\ 4 n|C| 4) hence, x ^ \B\ 4 or x ^ \C\ 4- Consider the first; the second is 

similar. If a: £ W* but x ^ |J3| 4, then x |2?|. Thus M,x \£B, so M, x \/=B AC. 

But in that case M,x \= ->(B A C ) and so x £ | ->(B A C ) |. And since x £ W*, 
x £ |— >(.B A C) | 4- Thus -(InF) C |->(2?AC')| 4- (h) Suppose x £ |-i(HAC)| 4- 
Hence x £ W* and x £ | ->{B A C)|, i.e., M, x |= ->(B A C). Then M,x \/=B AC, 
so M,x \£B or M,x \£C, i.e., x ^ |J3| or x |C|. Consider the first; the second 
is similar. If x ^ |H|, then x ^ \B\ 4, so x ^ |H| 4 f~l |C| 4) and x ^ X n Y. 

But since x £ W * , x £ — ( X n Y). Thus | ->(B Ad) C —(A n Y). Putting (i) 

and (ii) together, —(A n F) = | ->(B AC)| 4- Therefore, since —(A n F) ^ O*,, 
| ->{B A C)| ^ O a *. By Proposition 1, \~>(B A C)| = — (|H| n |C|), where here — 
represents complementation with respect to W, i.e., |-i(HAC)| = W — {\B\C\\C\) . 
Since obviously both |H|, |C| £ Em , and since \B\ £ O a • and |C7| £ O a * and 
— (|H| fl |C|) £ O a », \B\ fl \C\ £ O a * because M meets model condition (b) ,m . 
Hence \B A C\ £ O a *, by Proposition l.i. Therefore, there is a D , namely B AC, 
such that D £ S' and AflF = |D| 4 and |D| £ O a * ■ That suffices for AflF £ O*, , 
as required. 

For (d), suppose for reductio that 0 £ 0*„ . Then there is a B £ S' such that 
0 = |B| 4 and |H| £ O a * ■ Plainly, 0 = 04- Hence, 0 4 = |-B| 4- So 0 = |J3|, 
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by Lemma 4. But then 0 £ O a «, contrary to M’s satisfying condition (d) m . 
Therefore, 0 ^ O *, , as required. □ 

Next, we show that M and Ad* are equivalent modulo ip; or, more precisely, 
first: 

Lemma 6. For all A £ ip and all a* £ W* , M, a* \= A iff M* ,a* f= A. 

Proof. By induction on A. Consider a* £ W* . Suppose A is atomic, i.e., A = p. 
Since a* £ W* , a* £ v(p) iff a* £ v(p) 4- Hence, immediately, M, a* (= p 
iff M*,a* |= p. Suppose the lemma holds for B,C £ ip. If A = B A C and 
A £ ip, then B £ ip and C £ ip, since ip is closed under subformulas. Hence, 
M,a* |= B A C iff Ad, a* \= B and M, a* f= C iff, by the inductive hypothesis, 
Ad* ,a*\=B and Ad* ,a* |= C iff Ad* ,a* |= B A C. The cases where A = B V C 
and A = -<B are similar. 

Before considering the case of A = OB, it is helpful to note, that under the 
inductive hypothesis, 

Proposition 7. For all B £ ip (less than A), |H|m* = \B\m 4 

For consider any B £ ip (to which the inductive hypothesis applies), (i) Suppose 
x £ \B\m*, i.e., M*,x \= B. So, by the inductive hypothesis Ad, x (= B and 
x £ \B\m- But since \B\m * C W* , x £ W* , so x £ \B\m 4- Hence \B\m* C 
\B\m 4- Likewise, (ii), suppose x £ \B\m 4 s ° that x £ \B\m, i.e. , M,x\= B, and 
x £ W*. Hence the inductive hypothesis applies and M*,x \= B, i.e., x £ \B\ M *, 
and so \B\ M 4 C |S| M ». Both together yield \B\ M * = \B\ M 4, as desired. 

Returning to the case of A = OB, ii A £ ip then B £ ip since ip is closed 
under subformulas. Hence B £ F. (i) Suppose M,a* (= OB. Then \B\m G O a *• 
By the preceding Proposition, |R|m* = \B\m 4- Hence there is a formula D, 
namely B , such that D £ F and \B\m* = \D\m 4 and \D\m G O a *• That suffices 
for \B\ m * £ O*,, which suffices for M*,a* \= OB. (ii) Suppose Ad*, a* |= OB, 
so that \B\m* G O*,, and thus by the preceding Proposition \B\m 4 € O*,. 
Therefore there is a C £ F such that \B\m 4 = \C\m 4 and \C\m £ O a *. 
\B\m = \C\ M , by Lemma 4. Since \C\m G O a *, \B\m G O a *, which suffices for 
M, a* |= OB, as required. □ 

The equivalence of M and Ad* (modulo ip) follows immediately, with Propo- 
sition 6.iii. 

Corollary 2. For all A £ip, Ad \= A iff Ad* (= A. 

From these lemmas we can now quickly establish frame-completeness for 

DPM. 

Theorem 3. (i) DPM.l is complete with respect to the class of frames, T A, 
that satisfy conditions (a), (b) and (c) as originally stated; (ii) DPM. 2 is com- 
plete with respect to the class of frames, T. 2, that satisfy conditions (a), (b)' , 
(c) and (d). 
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Proof. Consider both versions simultaneously. Take any formula A such that b 
A. By the model-completeness theorem, Theorem 2, there is a model M = ( F , v) 
meeting the respective model conditions such that A does not hold on M, i.e., 
with F = (W,0), there is an a € W such that M,a A. Let ip be the set of 
subformulas of A: plainly A € if. Let M* = ( F*,v *), with F* = (W*,0*), be 
the model derived from the filtration of M through ip as described above leading 
to Lemmas 5 and 6. There is an a* € W* such that a =,/, a*, by Proposition 6. 
By Lemma 6, M*, a* \£A. Moreover, by Lemma 5, F* meets the requisite frame 
conditions, and so F* € F . Therefore, there is a model on a frame in F on which 
A does not hold, and so A is not valid with respect to the class of frames, F, that 
meet the requisite frame conditions. Or, by contraposition and generalization, if 
a formula A is valid with respect to that class, it must be provable in DPM. □ 

This completes the principle result that was to be established here, that 
DPM is characterized not only by the class of models that meet conditions 
(a) m , (b) m , (c) m , or (a) m , (b) ,m , (c) m , (d) m , as appropriate, Theorem 2, but 
by the class of frames that meet (a), (b), (c), or (a), (b)', (c), (d), Theorems 
1 and 3. Furthermore, we notice that the models M* that falsify non-theorems 
of DPM are based on frames F* that are finite. Hence, with the corollary to 
Theorem 1, 

Corollary 3. (i) DPM.l is sound and complete with respect to the class of 
all finite frames that meet conditions (a), (b), (c); (ii) DPM. 2 is sound and 
complete with respect to the class of all finite frames that meet conditions (a), 

o>y, (c), (d). 

It follows that both versions of DPM have the finite model property, and because 
of their finite axiomatizability, it follows too that DPM is decidable. 

Corollary 4. DPM has the finite model property. 

Corollary 5. DPM is decidable. 

Let us now briefly consider the logics CDPM for conditional obligation 
that correspond most directly to DPM. The language of these systems, £ c , 
has all that is necessary for PC and also the single dyadic connective 0 (— /— ) 
such that 0(B/A) is well-formed whenever A and B are. P(B/A) abbreviates 
^0(-iB/A). CDPM.l is the least set of formulas containing, in addition to 
(PC), all instances of 

CN) b 0(T/T) 

CAND) b ( 0(B/A ) A 0{C/A)) 0(B A C/A) 

and closed under the rules, 

MP) If b A and b A — > B, then b B 
RCE) IfbdoB then b 0(C/A) o 0{C/B ) 

CRE) IfbBoC then b 0{B/A) o 0{C/A) 

CRPM) If b B — > C then b P(B/A) ( 0{B/A ) -► 0(C/A) ) 
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For CDPM.2, the counterpart to DPM.2, replace (CAND) with 

CPAND) h (0(A/C) A 0{B/C) A P((A A B)/C)) 0((A A B)/C) 

CP) h -nO(_L/A) 

For the semantics, modify the neighborhood frames of DPM to treat obli- 
gation now not exactly as a property of propositions, but as a relation between 
them, so that 0(B/A) represents that the proposition expressed by B is obliga- 
tory under the condition expressed by A. More formally, let a dyadic neighbor- 
hood frame F = (W, O), with W as before, but now O assigns each a € W a 
set of ordered pairs of propositions (X,Y), i.e., O a C pW x pW. As before, a 
model M on such an F is a pair (F,v) with v(p) C W for each atomic formula 
p. |= is defined as usual, but now with 

TO(— /— )) M, a f= 0(B/A) iff <|A| M , \B\ M ) G 0 a 

where as before \A\m = {a : M,a |= A}. 

CDPM.l is sound and complete with respect to the class of frames that meet 
the following conditions, which are analogous to those for the frames for DPM.l, 
for all X,Y,ZC W, and all a G W, 

ca) (W,W)€O a 

cb) If (X, Y) G O a and (X, Z)&O a , then (X, Y n Z) G O a . 

cc) If Y C Z and (X, Y) G O a and (X, —Y) O a then (X, Z) G O a 

while CDPM.2 is sound and complete with respect to the class of frames that 
meet conditions (ca), (cc), and also 

cb)' If (X, Y) G O a and (X, Z) G O a and (X, -(Y D Z)) O a then 

<x,ynz) G o a 

cd) (X, 0) ^ Oa 

Theorem 4. (i) CDPM.l is sound and complete with respect to the class of 
frames that meet conditions (ca), (cb), and (cc); (ii) CDPM.2 is sound and 
complete with respect to the class of frames that meet (ca), (cb)' , (cc) and (cd). 

Proof Sketch. Soundness, as usual, is merely a matter of verifying that the axioms 
are valid and the rules preserve validity; this can be left to the reader. The 
same arguments as for Theorem 1 apply. The proof of completeness follows 
that of Theorem 3. First, define the canonical frame F c = (W c ,O c ) as usual, 
with W c the set of maximal consistent extensions of CDPM (either version as 
appropriate), and with O c assigning each a G W c the set of pairs 

O c a = {(X, Y) : 3A3B(X = [A] and Y = [B\ and O(B)A) G «)} 

M c = ( F c ,v c ) with v c (p) = {a G W c : p G a}. Lemma 1, that M c ,a |= 
A iff A G a is easily extended to the new formulas 0{B/C). Thus, suppose 
0{B/C) G a, then by the inductive hypothesis \B\m c = [B] and \C\m c = [C\. 
So {\C\ M o,\B\ M o) G O c a , and M c ,a j= 0{B/C). If M c ,a (= 0{B/C) then 
(\C\ M <=, \B\m c ) £ Oa- So there are D and E such that \C\m c = [D] and \B\m<= = 
E and O(E)D) G a. Since \C\m c = [C] and \B\m<= = [B], by the inductive 
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hypothesis, [C] = [D\ and [B\ = [E\. So b C £4 D and h B f> fi and thus 
0(B/C) £ a, by (RCE) and (CRE), which covers this case of the induction. 

Second, show that CDPM is model-complete with respect to the class of 
models that meet conditions corresponding to (ca), (cb), (cc) ((ca), (cb)', (cc), 
(cd)) when the X,Y,Z are restricted to expressible propositions, those in £m- 
This requires showing that M c meets these model conditions. The argument 
follows that under Theorem 2. 

Third, given a model M that falsifies a non-theorem, derive the alternative 
model M* as described for Theorem 3 with F* = (W*,0*) formed from the 
filtration through M as there described, with O* assigning each a* £ W* the 
set of pairs (X* ,Y*) such that 

(X*,Y*) £ O*. iff 3B3C(B £ f and C £ W and X* = |B| f and 
Y* = \C\ i and (\B\,\C\) e O a ) 

Following the argument for Theorem 3, one can then show that F* satisfies the 
conditions (ca), (cb), (cc) ((ca), (cb)', (cc), (cd)) when M satisfies the corre- 
sponding model conditions, and also that M and M* are equivalent modulo ip, 
and hence that M* falsifies A. That suffices to establish completeness. □ 

With completeness, by this argument, also come the corollaries, that both 
versions of CDPM have the finite model property, and so are decidable. 
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Abstract. We propose a computationally oriented non-monotonic multi-modal 
logic arising from the combination of agency, intention and obligation. We argue 
about the defeasible nature of these notions and then we show how to represent 
and reason with them in the setting of defeasible logic. 



1 Introduction 

This paper combines two perspectives: (a) a cognitive account of agents that specifies 
motivational attitudes; (b) modelling societies of agents by means of normative con- 
cepts [4], For the first approach, our background is the belief-desire-intention (BDI) 
architecture, where mental attitudes are taken as primitives to give rise to a set of In- 
tentional Agent Systems [23, 2]. This view has been proved to be interesting especially 
when the behaviour of agents is the outcome of a rational balance among their (possi- 
bly conflicting) mental states [3, 24], The normative aspect is based on some intuitions 
about agents and their societies, in which it is assumed that normative concepts play a 
decisive role, allowing for the co-ordination of autonomous agents [22, 10, 12]. 

Our approach has in general several points of contact with the BOID architecture [4, 
5, 8, 6], where a number of strategies are provided for solving conflicts among informa- 
tional and motivational attitudes. BOID provides logical criteria (i) to retract agent’s at- 
titudes with the changing environment, and so (ii) to settle conflicts by stating different 
general policies corresponding to the agent type considered. A realistic agent thus cor- 
responds to a conflict-resolution type in which beliefs override all other factors, while 
other agent types, such as simple-minded, selfish or social ones adopt different orders of 
overruling. As in the BOID architecture, our system is rule-based. In particular, it is de- 
veloped in the setting of Defeasible Logic. All components are represented as defeasible 
conditionals. A rule such as p =>k q means that, given p, this implies defeasibly agent’s 
belief that q. Our claim is to develop a constructive account of BDI multi-modal logics 
where the rules are meant to devise suitable logical conditions for introducing modali- 
ties. If so, rules may also contain modalised literals, as for example in Ip =^k q, where 
I is a BDI operator of intention. In the same spirit, possible conversions of a modality 
into another can be accepted, as when the applicability of Ip =>k q may permit to obtain 
Iq. Based on this intuitions, our focus will be on Bratman’s [3] concept of policy-based 
intention [11]. The relation between mental attitudes and non-monotonicity should not 
sound surprising. Recent works by Thomason [27] and on BOID confirm this trend. 
Such a connection, with regard to epistemic logics, has already received much attention 
in the AI community [19]. However, the notion of defeasibility may play a new role 
within a constructive theory of (modal) operators. As we said, our aim is to show how 
to introduce modalities in a (computationally oriented) non-monotonic formalism. In 

A. Lomuscio and D. Nute (Eds.): DEON 2004, LNAI 3065, pp. 114-128, 2004. 

© Springer- Verlag Berlin Heidelberg 2004 




Defeasible Logic: Agency, Intention and Obligation 115 



this way, the notion of defeasible derivability is crucial since rules for mental states and 
conditions for derivation involving them allow to introduce modal operators. This ap- 
proach is motivated by the inherent computational complexity of multimodal logics [13] 
and, often, the notion of modality adopted for agents systems is by its own nature non- 
monotonic and so does not lend itself to necessitation [11]. The use of non-monotonic 
logics in intention reasoning allows the agent to reason with partial knowledge without 
having a complete knowledge of the environment. This also helps the agent in avoiding 
a complete knowledge of the consequences. We outline a proof theory whereby one can 
reason about ways of maintaining intention consistency in BDI like agent systems. The 
new approach facilitates the designer of an agent system like BDI in describing rules 
for constructing intentions from goals and goals from knowledge. 

BOID system incorporates also obligations. This is crucial in characterising the in- 
terplay between internal and external factors. Such intuition is also adopted here and 
is framed as well within a non-monotonic setting. Even for this component, the logical 
aim is to devise suitable conditions for introducing modalities. Two questions may be 
decisive in this regard. First, it would be important to recast the logical nature of obli- 
gations and to investigate how defeasible logic, as described in the following sections, 
might capture the well-known defeasible character of deontic reasoning. A full anal- 
ysis of the above issue is outside the scope of the paper. However, it is at least worth 
mentioning that our framework avoids a difficulty that is recognised in the deontic lit- 
erature [7], The source of this difficulty is the closure, classically accepted in Standard 
Deontic Logic, of the obligation operator under logical consequence. We simply point 
out that these difficulties are avoided by developing a suitable notion of logical deriva- 
tion of obligations. In general, with the adoption of this strategy we preserve at least 
some basic properties of obligations such as the closure under logical equivalence and 
consistency. An important issue concerns the relation between obligations and mental 
states. As it is pointed out [5], a number of possible approaches are available. Here we 
focus shortly on some minimal principles that emerge from the agent specification ap- 
proach considered in [6]. In particular, as argued there, we may adopt, for example, the 
schema Op —> Ip, or analogous versions for the other mental attitudes. This axiom is 
the strong version of intentional nonn regimentation as it does not simply prescribe the 
consistency between obligations and intentions but states the inclusion of the former in 
the latter ones. This of course means that what is not intended is also not obligatory. 
Other principles, such as Op — + correspond to weak forms of norm regimenta- 

tion with regard to agent’s mental states. In this sense, they also express hard constraints 
on agent systems. A different principle that regulate the interaction between obligations 
and desires may be (Op A GOAL^/j) — -> This avoids that the output of a con- 

flict between an obligation and a desire is that of adopting a plan for obtaining what is 
desired. These principles can be easily encoded in our framework. 

Last but not least, our framework is enriched by the notion of modal agency [9] . This 
aspect differentiates this system if compared, for example, to BOID architecture. The 
same logical strategy — a rule-based approach to introduce modalities — is also applied 
to this case. In particular, we will devise a set of rules to encode the action transitions 
occurring, under certain circumstances, as the results of actions. 
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We will focus on the idea of personal and direct action to realise a state of affairs. 
This concept is usually formalised by the well-known modal operator E, such that a 
formula like E/p means that the agent i brings it about that p. Different axiomatisations 
have been provided for it but almost all include Etp — > p (T, i.e., successfulness), —E,T 
(No), ( EipAEjq ) — > Ej(p/\q) (C), and are closed under logical equivalence [25,9]. 
This analysis, however, is here integrated by focusing on the intentional character of 
actions. This is done for two reasons. First, in the light of the logical framework we 
have defined so far it is interesting to devise criteria for handling the specific interaction 
between actions, intentions and the other mental states. Second, the aim is to make 
more precise the logical meaning of the notion of direct action. In fact, as found in the 
literature [26], it is not possible to capture with E the difference between the modal 
qualifications “sees to it” and “brings it about”. Both are usually represented by this 
modal operator, despite the fact that the former expression exhibits a clear intentional 
character, whereas the latter may refer as well to unintentional actions [14]. Thus we 
introduce the operator Z to express intentional actions. It is characterised by all basic 
properties of E plus the schema Zp — > Ip, which cannot be in general valid for E. 

The interest of adding agency to a framework that includes cognitive states and 
obligations is evident. First, the simple combination of agency and deontic operators 
makes possible a more accurate representation of obligations directed to agents’ be- 
haviour, such as in the case of OZp. In addition, it allows to express the creation of 
obligations, as in ZOp. As regards handling conflicts between rules, new possible types 
of agents can be defined, according to the order of overruling we want to adopt. In this 
perspective, forms of regimentation may be introduced especially for the operator Z. 
Finally, it is possible to embed in the system a number of interesting properties, such 
as ZOp — » Ip, which completes what is stated by a reasonable and analogous schema 
without the operator of agency, namely, IOp — > Ip. 

Finally, a few notes on the meaning of rules for obligation, which emerge from fo- 
cusing on their interplay with the other components we have described so far. If rules 
define the conditions for the introduction of modal operators, when we deal with obliga- 
tions defeated by other components we may in fact adopt two different views. Suppose 
we have two rules like r\ : p =>z q (a rule for action) and ro : .v =>q —q (a rule for obli- 
gation). Both are applicable and r\ defeats r 2 . If so we cannot derive -q via ri and so 
O-q. In a first interpretation (applicability-based obligation), that a rule for action (but 
the same applies to other components such as beliefs) collides with a rule for obligation 
means that a normative violation has occurred [4], But if rj prevails, in our setting we 
cannot argue in favour of the occurrence of O-q. On the other hand, a violation of an 
obligation does not imply the cancellation of such an obligation [28]. The obligation 
is still in force. This means that the existence of the actual obligation O^q depends on 
the applicability of r 2 , independently of the effective derivation of its consequent. In a 
second interpretation (pure-derivability-based obligation) the existence of actual obli- 
gations depends on the effective derivation of the consequent of a rule. In this case we 
can argue as follows. On the one hand, the non-derivation of O^q means that, as soon 
as a violation occurs, iq is nothing but a special kind of prima facie obligation: when 
violated, it does not make sense to deduce its consequent as a real obligation. On the 
other, and more radically, since the obligations that count in the system are those which 
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are derivable, we may say that, in the event the action of the agent blocks the inference 
of ()-q, the agent is a sort of legislator within the system; similar considerations apply 
to when intentions override obligations. 



2 Basic Defeasible Logic of Agency, Intention and Obligation 

Usually modal logics are extensions of classical propositional logic with some inten- 
sional operators. Thus any classical (normal) modal logic should account for two com- 
ponents: ( 1 ) the underlying logical structure of the propositional base and (2) the logic 
behaviour of the modal operators. Alas, as is well-known, classical propositional logic 
is not well suited to deal with real life scenarios. The main reason is that the descriptions 
of real-life cases are, very often, partial and somewhat unreliable. In such circumstances 
classical propositional logic might produce counterintuitive results insofar as it requires 
complete, consistent and reliable information. Hence any modal logic based on classi- 
cal propositional logic is doomed to suffer from the same problems. On the other hand 
the logic should specify how modalities can be introduced and manipulated. Common 
rules for modalities are necessitation and RM. Consider the necessitation rule of nor- 
mal modal logic which dictates the condition that an agent knows all the valid formulas 
and thereby all the tautologies. Such a formalisation might suit for the knowledge an 
agent has but definitely not for the intention part and, consequently, not for a logic 
of intentional agency. Furthermore, many authors have expressed concerns about the 
meaningfulness of OT . Moreover, an agent need not be intending all the consequences 
of a particular action it does. It might be the case that it is not confident of them being 
successful. Thus the two rules are not appropriate for a logic of deontic agency. A logic 
of deontic agency should take care of the underlying principles governing the intention 
and the action of an agent. It should have a notion of the direct and indirect knowledge 
of the agent, where the former relates to facts as literals whereas the latter to that of the 
agent’s theory of the world in the form of rules. Similarly the logic should also be able 
to account for general intentions as well as the policy-based (derived ones) intentions of 
the agent. Finally it should offer facilities to describe obligations and the relationships 
between the various modalities. 

These are in short the main guidelines we will follow in this and the subsequent 
sections to develop a suitable framework to deal with agency, intention and obligation 
components. As we have argued so far, reasoning about intentions and other mental 
attitudes has a defeasible nature, and defeasibility is one of the proper characteristic 
of normative reasoning. Thus any system that aims at the integration of intentions and 
obligations, for example a multi-agent system, should cater for defeasibility. The two 
phenomena (mental attitudes and deontic notions) are both subject to defeasibility, but 
they might obey different and sometimes incompatible intuitions; thus we need a non- 
monotonic formalism that is able to deal with them in a flexible, efficient and modular 
way and should offers itself to a seamless integration of the relevant modal operators. 
Moreover we need an efficient and easily implementable system to capture the required 
defeasible instances. 

Defeasible logic, as developed by Nute [20] with a particular concern about com- 
putational efficiency and developed over the years by [ 17, 1], is our choice. The reason 
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being ease of implementation [18], flexibility [1] (it has a constructively defined and 
easy to use proof theory which allows us to capture a number of different intuitions 
of non-monotonicity) and it is efficient: it is possible to compute the complete set of 
consequences of a given theory in linear time [16]. 

A defeasible theory contains five different kinds of knowledge: facts, strict rules, 
defeasible rules, defeaters, and a superiority relation. In this section we consider only 
essentially propositional rules. Rules containing free variables are interpreted as the set 
of their variable-free instances. 

Facts are indisputable statements, for example, “John is a minor’’. In the logic, this 
might be expressed as minor(John). 

Strict rules are rules in the classical sense: whenever the premises are indisputable 
(e.g., facts) then so is the conclusion. An example of a strict rule is “every minor is a 
person”. Written formally: minor(X ) — » person(X). 

Defeasible rules are rules that can be defeated by contrary evidence. An example of 
such a rule is “every person has the capacity to perform legal acts to the extent that the 
law does not provide otherwise”; written formally: person(X ) hasLegalCapacity(X) . 
The idea is that if we know that someone is a person, then we may conclude that he/she 
has legal capacity unless there is other evidence suggesting that h/she may not have. 

Defeaters are a special kind of rules. They are used to prevent conclusions not to 
support them. For example: WeakEvidence -> guilty This rule states that if pieces of 

evidence are assessed as weak, then they can prevent the derivation of a “guilty” verdict; 
on the other hand they cannot be used to support a “not guilty” conclusion. 

The superiority relation among rules is used to define priorities among rules, that 
is, where one rule may override the conclusion of another rule. For example, given the 
defeasible rules 

r : personfX) =>■ hasLegalCapacity{X) 
r ' : minor (X) => -<hasLegaICapacity(X ) 

which contradict one another, no conclusive decision can be made about whether a 
minor has legal capacity. But if we introduce a superiority relation > with r 1 > r, then 
we can indeed conclude that the minor does not have legal capacity. 

A rule r consists of its antecedent (or body ) A(r) (A(r) may be omitted if it is the 
empty set) which is a finite set of literals, an arrow, and its consequent (or head) C(r) 
which is a literal. Given a set R of rules, we denote the set of all strict rules in R by R s , 
the set of strict and defeasible rules in R by R S( j . the set of defeasible rules in R by Rj, 
and the set of defeaters in R by Ifij, . R\q] denotes the set of rules in R with consequent 
q. If q is a literal, ~r/ denotes the complementary literal (if q is a positive literal p then 

is -i p\ and if q is — i /?, then is p). 

A defeasible theory D is a structure (F. R K . R 1 ,R Z ,R°, >) where F is a finite set of 
facts; R k , R 1 , R z and R° are, respectively, finite set of rules (strict, defeasible rules and 
defeaters) for knowledge, intentions, agency, and obligations; and >, the superiority 
relation, is a binary relation over the set of rules (i.e., > C (R K U R 1 1 R z U R 0 ) 2 ). 

Intuitively, given an agent, F consists of the information the agent has about the 
world, its immediate intentions, its actions and the absolute obligations; R K corresponds 
to the agent’s theory of the world, while R z , R 1 and R° encode its actions, policy, and 
normative system; > captures the strategy of the agent (or its preferences). The policy 
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part of a defeasible theory captures both intentions and goals. The main difference is 
the way the agent perceives them: goals are possible outcomes of a given context while 
intentions are the actual goals the agent tries to achieve in the actual situation. In other 
words goals are the choices an agent has and intentions are the chosen goals; in case of 
conflicting goals (policies) the agent has to evaluate the pros and cons and then decide 
according to its aims (preferences), which are encoded by the superiority relation. 

A conclusion of D is a tagged literal and can have one of the following four forms: 

+Aq meaning that q is definitely provable in D (i.e., using only facts and strict 

rules). 

—A q meaning that we have proved that q is not definitely provable in D. 

+dcj meaning that q is defeasibly provable in D. 

—dq meaning that we have proved that q is not defeasibly provable in D. 

Over the years a number of formulations of the proof theory of defeasible logic have 
been proposed (sometimes for variants of defeasible logic); here we will adopt the meta- 
program formalisation of [17]. 

The meta-program M assumes that the predicates, fact (Head) , superior (Rulel , 
Rule2), strict (Name , Operator, Head, Body), defeasible (Name , Operator, 
Head, Body) , and def eater (Name , Operator , Head, Body) , which are used to rep- 
resent a defeasible theory, are defined. The interpretation of the basic predicates of the 
meta-program is as follows: 



fact(p) iff p £ F 




strict(r, m, p, [ai,... 


A]) iff r\a t,.. 


■ ,a n — p G R s [p\ 


def easible(r, m, p, [a!,... 


> a n]) iff r:a u .. 


• ,Cln m P G Rj [p] 


defeater(r, m, p, [ai,... 


,a n ]) iff r:a u .. 


Ti a n ^ m P G Rdft\p\ 


superior]; 


r, s ) iff r>s 





According to the above predicates we introduce the definition of a rule. 



rule (R, 


X, 


P, 


[Ai , . 


• > A„] ) 


- strict(R, X, P, [Ai , . . . 


> A„] ) . 


rule (R, 


X, 


P, 


[Ai , . 


• > A„] ) 


- def easible (R, X, P, [Ai 


• ■ ■ j A„] ) 


rule (R, 


X, 


P, 


[Ai , . 


• > A„] ) 


- defeater(R, X, P, [A],. 


• , A„] ) . 



We are now ready for the clause defining the meta-program describing the proof-theory 
of defeasible logic 1 . If we disregard the modal operator it is immediate to see that 
the following meta-program has the same structure as the meta-programs given for 
propositional defeasible logic in [1, 17]. Essentially we have four (independent) copies 
of the same meta-program, one for each modality. 

1 We have permitted ourselves some syntactic flexibility in presenting the meta-program. How- 
ever, there is no technical difficulty in using conventional logic programming syntax to repre- 
sent this program. As usual with logic programming capital letters stand for variables, however 
we reserve K,0 , / and Z for modalities, and we will use X, Y, W for variables ranging over modal 
operators. 
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strictly(P, K):- fact(P). 
strictly(P, X):- fact(XP). 

strictly(P, X):- strict(R, X, P, [A] A„ , YjBi , . . . , Y„,B,„] ) , 

strictly(A], K) , strictly(A„, K) , 

strictly(B], Yj), strictly(B m , Y,„) . 

The first two clauses establish that a conclusion in strictly provable if it is one of the 
facts, while the third corresponds to modus ponens for strict rules and strictly derivable 
literals. Notice that the first clause is relative to rule for knowledge; as we have argued 
before the rules in R K are used to encode the description of the environment (and there 
is no modal operator K\). Thus unmodalized literals can be thought of as prefixed by a 
virtual K modal operator. 

def easibly (P , X):- strictly(P, X). 
def easibly (P , X):- consistent (P , X), 
supported(R, X, P) , 
not defeated(P, X, S) . 

consistent (P , X):- not strictly(^P, X). 

defeated(P, X, S):- applicable (S , X, ~P) , 
not overruled(^P, X, T, S) . 

overruled(P, X, T, S):- supported(T, X, P) , 
superior(T, S) . 

applicable (R, X, P):- rule(R, X, P, [Aj , . . . ,A„,YiBi , . . . , Y m B,„] ) , 

def easibly (A] , K) def easibly (A, ,, K) , 

def easibly (Bj , Yi), ..., def easibly (B,„, Y,„) . 

supported(R, X, P):- rule(R, X, P, [Ai A„,YiBi Y,„B,„] ) , 

def easibly (Aj , K) def easibly (A, ,, K) , 

def easibly (B i , Yi), ..., def easibly (B,„, Y,„) . 
not defeater(R, X, P, [Aj , . . . ,A„,YiBi , . . . ,Y,„B,„] ) . 

The first clause allows the transformation of a strict conclusion in a defeasible conclu- 
sion. A defeasible derivation of a literal p consists of three phases. In the first phase we 
establish that the opposite literal is not strictly provable and then have to provide an ap- 
plicable supportive rule for p (i.e., using the predicate supported (r , p) , where r is a 
supportive rule for p), then in the second phase we build all possible counterarguments 
against p (i.e,, def eated(p, s) meaning that the literal p is defeated by rule s) and we 
have to verify that the conclusion is not defeated by the attacking arguments, so we try 
to rebut the counterarguments (i.e., overruled(^p, t, s)) by stronger arguments 
for the intended conclusion. 

The relationship between proof tags on one hand and the predicates strictly and 
def easibly on the other is as follows: 

D b +Axp iff M\~ strictly(p,X) D b —Axp iff M b not strictly(p,X) 

D b +dxp iff MY- def easibly(p,X) D b —dxp iff MY- not def easibly(p,X) 
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Let us consider a theory where F = {la.h.Od.e} and R = {la.b =>-/ c; e,Zc =>q /}. 
Here we can prove +d/a, +c) K b, +r-) K e and \-d(jd since they are facts. Then the first 
rule is applicable and we can derive +dzc, and now the second rule is applicable and we 
obtain +dof- If we replace the first rule with la, b =>k c we conclude -\-b K c instead of 
+c)k(' and now the second rule is no longer applicable. We illustrate the theory with the 
help of a concrete example. A drunk surgeon intends to operate a patient. The surgeon is 
aware that operating under the influence of alcohol will result in a failure. Moreover the 
legal system under which the surgeon operates prescribes that people causing permanent 
damages as a result of negligence are responsible. Thus the two rules can be rewritten, 
respectively as 

I (operate), drunk fail 
permanent Damages, Z(fail) =>o responsible 

The conclusion is that the surgeon is responsible, because the damages are the result of 
an intentional negligence. What about when the surgeon, not on duty and being the only 
person able to complete the required medical procedure, is drunk and the patient will 
die without the operation? The surgeon knows that the patient will suffer permanent 
damages as a result of the operation, but he operates anyway. In this case we have to 
change the first rule in I (ope rate), drunk =>k fail- Here we derive +dxfail instead 
of +dzfail, and thus we block the application of the second rule. Hence we cannot 
conclude that the surgeon is responsible. 

3 Interaction among Agency, Intention and Obligation 

The program given in the previous section does not account for the properties of the 
modal operators and their mutual relationships. For these we have to introduce more 
clauses in the meta-program. 

strictly (P , K):- strictly(P, Z) . 
def easibly (P , K) : - def easibly (P , Z) . 

These two clauses enable us to convert a conclusion in Z in a conclusion in K , and thus 
they mimic the successfulness of the modal operator Z. 

Let us see now the relationship between the different kinds of rule we have intro- 
duced so far. Table 1 shows all possible cases and, for each kind of rule, indicates all 
potential attacks on it. Since we have defined four kinds of rules, we have to analyse 
twelve combinations, which are gathered in the table in six columns. Each column cor- 
responds to a type of potential attack, such that the second rule placed in each box is 
nothing but the potential attack on the first one. If the potential attack fails, since the 
superiority does not play here any role, this means that the case at stake does not corre- 
spond to a real attack: The type of rule that wins does so in any case and independently 
of inspecting the strength of the rules involved (i.e., without considering superiority 
relation). 

To represent the possible attacks we have to strengthen the definitions of the predi- 
cate consistent. 

consistent (P , X):- not strictly(~P, K) , 

not strictly(~P, Yj), ..., not strictly(^P, Y„) . 
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Table 1 . Basic Attacks 
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where Yj, . . . , Y„ are the modalities that attack the modality X, according to Table 1. At 
the same time, we have to allow more types of rule in the attack phase. 

applicable (R, X, P):- rule(R, Y, P, [Ai , . . . ,A„,WiBi W m B m ] ) , 

def easibly (A] , K) def easibly (A, ,, K) , 

def easibly (Bj , Wi), def easibly (B,„, W,„) . 

This clause is required for all Y that attack X in Table 1 . Moreover, if Y = Z we have to 
include, due to the successfulness of the operator, the additional clause 

applicable (R, X, P):- rule(R, Z ^XP, [Aj A„,YiBi , . . . ,Y m B m ] ) , 

def easibly (A] , K) def easibly (A, ,, K) , 

def easibly (B ] , Yi), def easibly (B,„, Y,„) . 

Table 1 (and, as we shall see, Tables 2 and 3) provides some basic criteria for classi- 
fying cognitive agents [8, 4], The general assumption of Table 1 is to deal with realistic 
agents. In other words, we set criteria for solving conflicts in which beliefs in gen- 
eral override the other components. In fact, our approach considers epistemic rules as 
agent’s basic principles of rationality about the world. The only exception to this view 
is that rules for action may attack rules for belief, since the former ones capture the 
mechanism that governs the factual results of (intentional) actions. We can speak in this 
case of quasi-realistic agents since, given a certain belief, a contrary evidence based on 
rules for action may prove that such a belief is false. Given this background, Tables 2 
and 3 will consider other agent’s types, such as selfish and social, plus further speci- 
fications deriving from more articulated criteria for solving conflicts. As we shall see, 
the double reading assigned to the rules for obligation will allow us to provide an alter- 
native interpretation of some already established criteria for handling conflicts between 
deontic factors, on one hand, and mental as well as action components, on the other. 

Let us focus on some examples for each type of potential attack described in Ta- 
ble 1. Suppose we have (first column from the left) ri : forest, dry, spark =>K.fire and 
i '2 : forest =>o ~fire. It is clear that rule r 2 does not determine a real attack on ri . Since 
we assume the agent is realistic, rule /q is nothing but a principle of rationality of the 
agent: It says that a fire is (defeasibly) the consequence of a spark in a dry forest. Rules 
like r\ must prevail with regard to deontic rules, such as ri that prohibits to light a fire 
in a forest. When r\ is attacked by ri, the output that follows from r\ is not affected by 
this attack and the fire should be obtained since this fact is independent from any rule 
that forbids to light fires in the forest. Vice versa, the derivation of the obligation not 
to light a fire is blocked since such an obligation is meaningless when the conditions 
for r i occur: Of course, ri does not apply when fire is obtained according to agent’s 
rationality. 
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Similar remarks apply to the case that involves rules for knowledge and intention 
(second column). Let us consider the rule r 3 : cautious =>/ -fire. Even here it is rea- 
sonable to argue in favour of r\ . Although agent’s being cautious means to intend not 
to light a fire, this intention does not necessarily override r\, namely the fact, according 
to agent’s knowledge, that a spark normally causes a fire in a dry forest. This means 
that, when r 3 attacks r\, the consequent of the latter must be obtained, while the re- 
verse attack should prevent to get I -fire since such an intention is meaningless when 
the agent assumes rationally that the fire must spread through the forest. Different ar- 
guments may be put forward when a rule for action, 14 : protect _spark =L/ -fire, is 
considered in combination with r\. Rule r 4 states the fact that fire obtains and may be 
viewed as a (factual) contrary evidence with regard to r\ . In general, rules like p =>■/ q 
say that a specific action preformed by agent, under certain circumstances, defeasibly 
determines through such action the occurrence of q, and so that Zq. The applicability 
of these rules may thus be a factual and contrary evidence with respect to A'-rules that 
would allow to infer ~^q. For similar (but opposite) reasons, the reverse attack (14 on 14) 
should block the derivation of -fire. 

Since we assume the rationality of the agent with regard to its knowledge about 
the world, we have set that rules for knowledge be greater in strength with regard to 
rules for obligation and intention. Actions may override knowledge while mutual at- 
tacks involving intentions and actions determine real attacks for the trivial reason that 
actions are intentional in character. It is obvious that, when we have a rule such as 
ip : incautious =>/ fire, the attack of ip on 14 prevents from obtaining -fire while the re- 
verse attack blocks the derivation of fire: Actions defined by rules for Z are intentional. 

On the other hand, as we have indicated in Table 1 , the interplay between obliga- 
tions, intentions and actions cannot be settled so easily. In the light of well-known dis- 
tinctions among different kinds of agent. Table 2 summarises all combinations related 
to the cases indicated in Table 1, first and second columns from the right. 

Table 2 . Type of Agent: Basic Attacks 
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Let us provide some brief comments. Independent and strongly independent agents 
are free respectively to adopt intentions and to perform intentional actions in conflict 
with obligations. In particular, within a pure-derivability-based interpretation of obli- 
gations (see Section 1), strongly independent agents may correspond to true cases of 
normative violation, since the actual obligation is derived in presence of a contrary ac- 
tion. As expected, for social and strongly social agents obligations override rules for 
action and for intention. In addition to the standard view [4], the overruling of inten- 
tions or actions with regard to obligations may configure a case of agent legislator, 
when, within a pure-derivability-based interpretation, only derived obligations count as 
such in the system. Pragmatic and strongly pragmatic are cases where no derivation is 
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possible and so the agent’s behaviour is open to any other course of action other than 
those specified in the rules considered. To illustrate the potential conflicts between obli- 
gations and intentional acts we examine the well-known prisoner dilemma. Two people 
are arrested for a major crime, however the police does not have enough evidence to in- 
criminate them, but they can be charged with and convicted for a minor crime. However 
if one of them confesses the crime she will be sentenced to one year and the other to 
twenty-five years. If both confess they will be imprisoned for ten years each. Finally if 
none of them confesses then they have to serve for three years each. The two criminals 
are part of a criminal organisation renowned for its code of honour that prescribes to not 
betray your fellows. The best individual outcome is to confess the crime, while the best 
outcome according to the organisation code is not confessing it. Hence this situation 
can be represented by the following theory: 

=>z confess =4>o confess 

A “selfish criminal” will confess ( +dzconfess , -do -> confess ), giving thus priority to 
his welfare, while a “social criminal” will stick with the code of honour and will not 
confess the crime (+do^confess, —dzconfess). 

Table 2 does not cover all possible types of agent. In fact, the focus is there on 
possible attacks that involve only two rules. Table 3 completes the scenario and provides 
all possible combinations when we deal with three rules. It is worth noting that we 
consider only the case with p, =>/ and =>/ ~p: The case with =>/ ~p and =>z p 
is meaningless since rules for Z govern only intentional actions. For similar reasons, 
some combinations in Table 3 are excluded (as highlighted by adding three question 
marks). Some comments on Table 3. Strongly independent agents are basically as in 
Table 2 because Z implies I. The types hypersocial and hyperpragmatic do not add 
conceptually anything with respect to their corresponding and weaker versions of Table 
2. The new cases are the selfish saint, sinner and social sinner types. The first is given 
when the content of agent’s intention is in conflict with an obligation, but no intentional 
action to realise such a content is performed. The sinner performs this action and, in 
parallel, the obligation is defeated. The social sinner has this intention, the derivation of 
the obligation is blocked but no violating action is performed. Once again, notice that 
sinner and social sinner may viewed, within a pure-derivability-based interpretation, as 
peculiar cases of legislator. 



Table 3. Type of Agent: Other Attacks 
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Another interesting feature that could be explained using our formalism is that of 
rule conversion. For instance, suppose that a rule of a specific type is given and also 
suppose that all the literals in the antecedent of the rule are provable in one and the 
same modality. If so, it is possible to argue that the conclusion of the rule inherits the 
modality of the antecedent. To give an example let p. q =>k r denote that an agent knows 
r given p and q (or r is a consequence of p and q). Now suppose I(p') and I(q) are given. 
Can we conclude /(/-)? Here we should be careful about the interpretation of the rules 
as p —*k q (q is a consequence of p), p q (given p, q is obligatory), p q (given 
p the agent has the intention q), and p =A/ q (given p the agent sees to it that q). 

The adoption of conversions should not sound strange. In many formalisms it is 
possible to convert from one type of conclusion into a different one. Take for example 
the right weakening rule of non-monotonic consequence relations, where B\- C and 
A imply A (~C (see, e.g., [15]). In other words, it allows the combination of non- 
monotonic consequence with classical consequences. While not every combination of 
obligations and mental attitudes or action concepts will produce meaningful results for 
the conversion, some of them can prove useful in the present context. For example if 
we want to convert rules for knowledge/belief into rules for obligations we have to de- 
termine conditions under which a rule for knowledge can be used to directly derive an 
obligation. The condition we have after is that all the antecedents on the rule can be 
shown to be obligatory. In general, when we admit conversion of rules, the situation is 
such that when given environmental conditions are satisfied a rule for X is transformed 
in a rule for Y ; accordingly we have to use the “transformed” rule both in the support 
and attack phases. The conditions under which a rule can be converted are that all im- 
personal literals are (defeasibly) provable in K and all personal literals are (defeasibly) 
provable in the modalities required by the conversion (see Table 4). Formally we have 

supported (R, X, P):- rule(R, Y, P, [Aj , . . . , A„] ) , 
environment (A] , W) , ..., environment (A„, W) , 
not defeater(R, X, P, [Ai , . . . ,A„] ) . 

applicable (R, X, P):- rule(R, Y, P, [Aj , . . . , A„] ) , 
environment (A] , W) , ..., environment (A„, W) , 

where 

environment (P , X):- personal (P), defeasibly (P , X). 
environment (P , X):- not personal(P), defeasibly(P, K) . 

The relationships among the modalities X, Y and W are described in Table 4 2 . Notice 
that not all cases in the Table 4 can be accepted for all types of agents: the first column 

2 Table 4 should be read as follows. The first and second columns indicate the modal qualifica- 
tions of the antecedents of a rule. The third column specifies the type of rule while the fourth 
provides the possible modal qualification we may obtain in the light of the antecedents and the 
rule type. Fifth column says whether the corresponding conversion holds in all cases or charac- 
terises only some particular agent types. For example (fourth row from the top), if Zp,Iq =>k r 
is applicable we may obtain +d/r. On the other hand, the derivation of +djr from Ipjq =>o r 
is possible only if we assume a kind of norm regimentation, with which we impose that all 
agents intend what is prescribed by deontic rules. 
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Table 4. Conversions 
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from the right indicates new types of agent corresponding to each rule conversion. This 
is particularly evident when obligations, actions and intentions are considered. Other 
combinations than those here defined are possible but they are problematic. As we can 
see, some of the conversions above logically characterise new types of agents. Let us 
focus on them. All these types correspond to weak versions of strong norm regimen- 
tation. Strong regimentation, as maintained in [6], corresponds to adopting schemata 
like Op — > Ip. The just mentioned conversions configure weak forms of regimentation. 
For instance, consider the conversion described in the fifth row from the top. Roughly 
speaking, if we want to give an intuitive reading we could conceive it as follows: Ip and 
0(p — > q) entail Iq. Let us see with a concrete example the meaning of some conver- 
sions. The Yale Shooting Problem can be described as follows 3 

live Ammo, load, shoot kill 

This rule encodes the knowledge of an agent that knows that loading the gun with live 
ammunitions, and then shooting will kill her friend. This example clearly shows that the 
qualification of the conclusions depends on the modalities relative to the individual acts 
“load” and “shoot”. If the agent intends to load and shoot the gun ( I {load ), I(shoot)), 
then, since she knows that the consequence of these actions is the death of her friend, 
she intends to kill him ( -\-djkill ). Similarly if she intentionally loads the gun and intends 
to shoot ( Z(load ), I(shoot)). To intentionally killing him she has to load and to shoot 
the gun intentionally ( Z(load ), Z(shoot)). If she intentionally loads the gun (Z(Ioad)) 
and accidentally shoots it (shoot), she kills the friend (+dKkill) but this is not an in- 
tentional act (—dzkill), since not all the actions leading to this dramatic conclusion are 
intentional. Finally in the case she has the intention to load the gun ( +diload ) and then 
for some reason shoot it (shoot), then the friend is still alive (—dickill). 

So far we have only examined cases where we pass from a single modality to a dif- 
ferent modality. However axioms ZOp — > Ip and IOp — > Ip provide modal reductions. 
These principles can be described in the meta-program by the following clause 

3 Here we will ignore all temporal aspects and we will assume that the sequence of actions is 
done in the correct order. 
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def easibly (P , I):- def easibly (OP , Z) . 
def easibly (P , I):- def easibly (OP , I). 

Moreover we have to add clauses for applicable and supported where we consider 
rules for Z and / with conclusion Op when rules for I with conclusion p/~p are admis- 
sible. 

4 Related and Future Work 

Let us sketch just some short conclusions, also for future research. 

Nute [21] proposed a Deontic Defeasible Logic which, in some respect, is similar to 
the framework presented here. Beside some minor differences in the way rules are han- 
dled at the propositional level, the main difference is that he uses only one type of rule. 
Traditionally, in proof-theory, rules to introduce operators give the meaning of them. 
Thus using one and the same type of rule both for obligation and factual conclusion 
does not show the real meaning of the operators involved. Moreover it is not clear to 
us whether and how complex conversions and reductions can be dealt with in a system 
with only a single type of rules. 

As we said, another reference of this paper is to BOID. Its calculation scheme is 
similar to the one proposed here. For example, as in BOID it is possible to state gen- 
eral orders of overruling but also local preferences involving single rules. This last job 
is made here by means of the superiority relation. However, our system, which also 
deals with agency, is designed to take care of modalised literals and modal conversions. 
This is due to the logical task assigned to the rules. For this reason, but in a different 
perspective, our logical view may be also useful to study the notion of negative per- 
mission. In fact, conditions for dop may also determine the implicit introduction of a 
modal operator of permission in terms of non-derivability of an obligation. 

As regards the complexity of the system, [16] has proved, for the propositional case, 
that the set of tagged literals can be derived from the theory in linear time in the number 
of rules in it. It is not hard to extend this result to the modal case. The distinction of 
different kinds of rules does not affect the complexity of the theory. The case for K 
is the same adopted in standard Defeasible Logic while, for the other components, we 
convert relevant rules into the appropriate “extended” modal literals. At this point, the 
inference mechanism is the same as the standard one. 

Due to space limitations it was not possible to show how to model other notions of 
agency — such as capability (both practical [9] and deontic [12]), attempt, and so on — 
that have received some attention in the literature in the past few years. Here it suffices 
to say that those notions can be easily represented (modularly) by adopting a strategy 
similar to that used in [1 1] to derive goals from intentions in a BDI defeasible logic. 
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Abstract. This work addresses the issue of obligations directed to 
groups of agents. Our main concern consists in providing a formal anal- 
ysis of the structure connecting collective obligations to individual ones: 
which individual agent in a group should be held responsible if an obli- 
gation directed to the whole group is not fulfilled? To this aim, concepts 
from planning literature (like plan and task allocation) are first used in 
order to conceptualize collective agency, and then formalized by means of 
a dynamic deontic logic framework. Within this setting, a formal account 
of the notion of coordination, intended as management of interdependen- 
cies among agents’ activities, is also provided. 



1 Introduction 

In multi-agent systems, the cooperation between agents is an important issue. 
For that purpose several theories have been developed about joint goals, plans 
and intentions. All these joint attitudes try to capture some of the team elements 
of agents that work together. In this paper we follow up on that work and 
will look at collective obligations. What are the consequences for an agent if 
the group in which an agent performs its tasks gets an obligation to fulfill a 
certain goal? E.g. a program committee of DEON’04 may have the collective 
obligation to review all submitted papers before a certain time. We are interested 
to explore how this collective obligation translates into individual obligations for 
the program committee members, e.g. review two or three papers, and the extra 
obligations for the program chair to divide the papers and monitor the process 
and make final decisions. 

In [12], the collective obligation is formalized in a framework of deontic logic, 
which gives the opportunity to express which agent (or which group of agents) 
has the responsibility to bring about a certain situation (to express group liabil- 
ity, e.g. liability for a trading partnership) and to express the relation between 
the agents of a group. However, in the theory developed in [12] we cannot express 
the individual responsibility that follows from the task to achieve the fulfillment 
of the collective obligation. A consequence is that we cannot indicate which 
individual is responsible for a violation of a collective obligation. 
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We believe that the main differences between individual and collective obliga- 
tions can be explained through the distribution of responsibility and knowledge. 

If an individual has an obligation he has to perform all tasks for the fulfillment 
of the obligation (including planning the tasks) himself. Therefore whenever the 
obligation is not fulfilled the cause is that the individual did not perform a task 
that should be done to fulfill the obligation. It follows that, whatever the actual 
task was that was not performed, the individual is responsible. This differs fun- 
damentally from the situation where a group has to fulfill the obligation. In this 
case the tasks are distributed over the group. Each individual can independently 
(autonomously) decide to perform his task or not. The responsibility therefore 
also is distributed over the members of the group. If the group does not fulfill the 
obligation the individual that did not perform his task will be held responsible! 
So, it becomes important to check exactly which are the obligations for each 
member of the group that follow from the collective obligation of that group. 

The second aspect that is very different between collective and individual 
obligation is the distribution of knowledge. An individual can decide for himself 
whether to fulfill an obligation or not, based on its utility, beliefs, goals etc. 
The individual also knows the complete plan, whether he is capable to perform 
the actions in the plan, when he has performed actions or decided not to per- 
form them. All this information is readily available and can be reasoned about. 
However, when a collective obligation is divided over the individuals of that col- 
lective, they might not know the whole plan, typically do not have information 
about actions that are performed, etc. 

We make the important assumption that an individual can only be responsi- 
ble for violating an obligation if he knows (or could have known) that he has the 
obligation. If a group has a collective obligation, but a member of the group does 
not know what are the consequences of that obligation for himself, he cannot be 
held responsible for violating that part of the obligation (unless he knows he has 
the obligation to find out what he has to do, but never bothered to do it). This 
assumption has many consequences for the desired dissemination of knowledge 
through the group about the plan, plan allocation and current execution of the 
plan, etc. In the ideal case all members of the group have complete knowledge 
about all these aspects, such that no member can avoid his responsibility based 
on a lack of knowledge. It leads to the introduction of explicit coordination ac- 
tions in our model to incorporate this aspect of the collective obligation. We will 
discuss these in detail in Section 2. 

Coordination actions are actually only one type of meta actions that should 
be considered. Besides the plan to achieve the content of the obligation the group 
should create that plan, allocate agents to parts of the plan, create a plan for 
what to do when the original plan fails, etc. These meta actions should also be 
coordinated again creating in the end an infinite regression of meta actions. In 
this paper we will not take all these layers into account, but will limit us to the 
coordination actions that are necessary during the execution of a plan to fulfill 
the obligation. 

In the next section we will discuss the notions of collective agency, plans, 
task allocations and coordination of tasks. This will indicate which concepts 




Collective Obligations and Agents: Who Gets the Blame? 131 



are needed in the formal framework to describe collective obligations and their 
consequences. The formal framework is described in Section 3. In Section 4, we 
show how the formal framework can be used to model an example and how some 
consequences of collective obligations can be derived depending on characteristics 
of the obligated task, structure of the group and their knowledge. In Section 5 
we draw some conclusions and give directions for future research. 

2 Conceptualizing Collective Agency: 

Plans, Allocation, Coordination 

In this section we discuss two basic issues that underlie the analysis of the 
consequences of a collective obligation for the individuals of the group. First we 
discuss the notion of a (distributed) plan to achieve the collective obligation. 
After that we discuss some of the coordination issues around these distributed 
plans. During the discussion we will make use of the notation of the formal 
framework that is fully described in Section 3. The intuitions and properties 
described here do not depend on this formalism though! 

2.1 Concepts of Plan and Task Allocation 

To fulfill a collective obligation 0 (X : 7), the group X has to perform a complex 
action 7 1 . The concrete manner to deal with such a complex action is planning. 
The group has to decompose the complex action into a number of individual sub- 
actions. For example, if the program committee is obliged to notify the authors 
of the submitted papers of acceptance before a certain deadline, this obligation 
can only be fulfilled if the work that has to be done, is shared out in several 
tasks over the members of the program committee. Therefore, the group needs 
a plan: a concrete manner to achieve the task of the group. 

We can define a plan to perform the complex action 7 as a decomposition of 
the complex action 7 by a sequence of (possible simultaneous) individual actions: 

Plan{ 7) = («i • a-i • . . . • a n ) such that 7 = aq • 02 • • • • • cr n , 

where • stands for the simultaneous operator or the sequential operator 
The action aq&a^ stands for the simultaneous performance of oq and 0:2, and 
action oq; a.^ stands for the sequential composition of oq and 

We need the simultaneous operator, since some actions have to be performed 
at the same time. The sequential operator is needed because some actions might 
depend on other ones: a certain action can only be performed if an other action is 
done. So, the plan must at least determine the order of sub-actions. For example, 
the notification of acceptance of a certain paper can only be done if it is reviewed 
by the delegated members of the program committee. The responsibility of the 
performance of an action a by an agent depends not only on the individual who 
is committed to perform the action a, but also on agents who have to perform 
actions which are necessary to perform action a. 

1 Such a complex action 7 may be seen as equivalent to an action of the type 
achieve{r) , where r is a state of affairs. 
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The complex action 7 does not contain a non-deterministic choice, because 
we only use totally ordered plans [15]. However, there can be several totally 
ordered plans to execute a certain action 7, and it therefore makes sense to talk 
about a choice of plans. In this paper we restrict ourselves to acceptable plans, 
which are plans containing individual actions that can be performed by an agent 
in the group. In other words, for every individual action a there is an agent of 
the group which is capable of performing a. Note that there are better and worse 
plans. E.g. a plan that consists of individual actions that only can be performed 
by one agent seems worse than a plan that consists of individual actions that can 
be performed by several agents. Since there are several possible ways to divide 
the task, the group has to decide which plan should be followed. 

Besides task division (the decomposition of a complex actions 7 into indi- 
vidual sub-actions 07,. . . ,a n ), task allocation is needed, which indicates which 
(capable) agent of the group has to perform which sub-action of the complex 
action. We use the following definition for (partial) task allocation: 

Definition 1 . (Partial task allocation) A partial task allocation for a task 7 
within a group of agents X is defined as follows: 



< 1 1 : ai • I 2 ■ 02 • • • • • I n : a n > such that 

7 = 01*02* ... *a„, andIj£V + (X) for j = l, 2 ,...,n. 

We refer to the set of all partial task allocations of 7 within X as PPlan(X : 7) 

A partial task allocation is thus a composition of constructs of the type “group 
/ performs the (possibly complex) action o” (/ : o). These constructs are called 
(collective) events ([12]). 

Definition 2 . (Complete task allocation) CP is a complete task allocation 
for a task 7 to a group X , iff CP € PPlan(X : 7) and for all Ij occurring in 
CP holds that Ij={aj} 2 . 

E.g. let CP € PPlan({ai, 0,2, 03}, 7) and CP = (ai : ai ; 02 : 02 & <23 : 03). In 
CP agent 02 is responsible for the performance of action 02, but according to 
the plan he can only perform his action after agent ai has done action 07. The 
same holds for agent <23. 

The collective obligation 0 (X : 7) can be translated by the group X in inter- 
nal obligations of the group given a plan. E.g. given that we have 0({ai, <22, <23}, 7) 
and plan CP above. Then we would at least have that: 

0 (ai : ai) A [ai : 07 }{ 0 {a 2 : a 2 ) A 0 {a 3 : a 3 )) 

Which states that first ai is obliged to perform <27 and if a± has performed 
07 ([<21 : oi]) then a 2 and <23 are obliged to perform 02 and 03 respectively. 
In general, we have that given a complex collective obligation, a disjunction of 
all internal obligations, which are determined by the possible acceptable plans, 

2 In what follows, in order to keep formal expressions more readable, we will often 
refer to singletons omitting the {.} standard notation. 
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can be derived. The fulfillment of one of these internal obligations leads to the 
fulfillment of the collective obligation. Violation of the internal obligation leads, 
typically, to a decision to make another plan establishing an alternative internal 
obligation, or to the violation of the collective obligation itself. 

The above indicates how a plan can be used to distribute a collective obliga- 
tion over the members of a group. However, it also shows that the obligations of 
at least some members (in the example above <22 and <23) depend on the perfor- 
mance of an action of another member of the group (in the example above ai). 
This observation leads us to the issue of coordination between the actions in a 
plan. 

2.2 The Problem of Coordination 

The view on coordination, which is assumed here, can be perfectly summarized 
by the following quotation from [5]: 

“coordination is the process of managing interdependencies between ac- 
tivities” . 

Plans and task allocations, as they have been defined in Section 2.1, are es- 
sentially sequences of, respectively, simpler actions and events. This sequential 
structure is precisely what should be managed by means of coordination. Let us 
reconsider our example about the group organizing the DEON’04 workshop: for 
each submitted paper a reviewing process takes place, which ends, in some cases, 
with a notification of acceptance. The first question coming naturally about is: 
when should the agent responsible for notifying acceptances start his activity? 
I.e. how does he know that the condition for his obligation to send the notifica- 
tions is true? In the introduction we mentioned that we only consider an agent 
responsible for violating an obligation when he knows he has the obligation. 
We assume that if an agent knows the plan to fulfill the obligation and knows 
that the actions he depends on are performed he will also know that he has an 
obligation to perform his own part. Using the example and the notation used 
before plus Bi to denote the beliefs of agent ai and DONE (a : a) to indicate 
that agent a has performed a we get: 

62 ([<21 : ai](0(a2 : 0:2)) A B2(DON E^ai : 01)) — > -62(0(02 : 0:2)) (1) 



This suggests that 02 should somehow come to believe that a\ performed its 
task 3 . We do assume that an agent believes it performed a task whenever it did 
so (internal monitoring or conscious behavior) but this leads only to: 

[ai : a)(DONE(ai : a) A BiDONE(ai : a)) 

3 Note, in passing, that beliefs update issues might come about in relation with formula 
1. For example: how does the set of beliefs of an agent evolve? We leave these issues 
aside focusing exclusively on some formal aspects concerning the interaction between 
beliefs and obligations. This makes sense especially because beliefs will be considered 
essentially as the effect of coordination activities. 
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and not to: 

[a, : a](DONE(ai : a) A BjDON E{ai : a)) 

for any j ^ i. 

The latter can only be achieved through the introduction of explicit coordina- 
tion actions. This constraint determines the necessity for agents to be informed 
at least about what the previous agent did. And such a necessity impinges on 
the task decomposition itself forcing it to take into consideration how to provide 
agents with the necessary information to act according to the established plan. 
A task allocation ai : a ; <22 : /? for the complex action 7 for the group X, once 
taken into account this type of coordination problem concerning informational 
issues, becomes something of this kind: 

a\ : a ; at : coordinate^!, a, Y) ; <22 : f 3 

where a,; £ X and Y C X with F / 0 . The coordinate action is here understood 
as an action after each execution of which a belief holds in each agent belonging 
to Y which concerns an activity executed by the previous agent. Notice that 
Y should always be such that it contains at least the agent responsible for the 
task that follows within the task allocation sequence: so if <ij-\ is the preceding 
agent, Y should be such that « 7 £ Y. Notice moreover how the coordination 
action assumes different intuitive meanings depending on the agent appointed 
to its performance. In the example above we have that possibly a.) = a\ or 
ai = a-2- In the first case the coordinate action becomes a kind of informative, 
the agent itself being the one providing information about its performance: 

[aj - 1 : at\[aj - 1 : coordinate(dj_i, a, Y)] B^DON E(aj_ 1 : a) 

ak&Y 

and 3 ak £ Y s.t. a*, = aj. In the second case the coordinate action turns out to 
correspond to a sort of checking , since it is the agent himself which acquires the 
necessary information before acting: 

[<Zj_ 1 : a] [a : j : coordinate(aj_i, a, Y)] B^DON E(aj- 1 : a) 

a k GY 

and da*, £ Y s.t. a*, = a j. Notice, in the end, that even a “third party” might 
be responsible for this coordination task. 

Due to the introspection principle for agents concerning their actions the 
coordination action between two actions of the same agent becomes superfluous 
and takes the form of a so-called skip action: 

a,; : a ; a, : coordinate^,;, a, {oj}) = a* : a ; a, : skip. 

The property expressed in formula ( 1 ) relates the beliefs of an agent about 
the plan and the directly preceding actions to his own obligations. One might 
also be interested in the fact that an agent that is obliged to perform an action on 
which your actions depends does not perform his action. In the above example, 
in which Y = {02, as}, we could have: 

0 (ai : ai) A [af : ai][ay : coordinate^, ai, {02, 03})] 
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(B 2 (^DONE( ai : «i)) A B 3 (^DONE(a i : m)). 

where a\ : a\ denotes the negation of an event. Adding this feature enables 
the coordination task to take care that both in the case when an action is 
performed as scheduled as well as when an action is not performed as scheduled 
the dependent agents get to know about it. Further coordination mechanisms 
are usually devised which remedy the violation of an obligation by one of the 
agents ([16]). We will not get into this aspects in this paper yet. 

In the next section we will describe the formal framework in which the dis- 
cussions above can be expressed formally and which provides the right validities 
to indeed prove the properties that we would like to have in order to distribute 
the collective obligations over the individuals of a group. 

3 A Formal Framework 

Our aim is to further pursue a line of analysis, which has been already proposed 
in [13,12], trying to provide a formal framework in which to account for the 
problems of collective obligation and collective agency in terms of the concepts 
introduced in the previous section. Some attempts to formally address these 
problems have been already proposed ([1, 3,4]), but none of the frameworks pre- 
sented so far possesses the necessary expressive power for dealing with concepts 
such as plan and task allocation. One of the main reasons is that they are basi- 
cally grounded on stit or bringing-it- about action logics, which cannot cope with 
any specification of the internal structure of plans. 

More technically, this framework should handle event expressions, that is 
expressions about the performance of some action by some agents, and their 
composition, doxastic expressions, deontic expressions concerning event expres- 
sions, predicates on events. The framework is obtained expanding the proposal 
contained in [12] in several directions: first of all adding transactions and nega- 
tions on transactions, following the line described in [6]; then adding doxastic 
logic; and finally adding a type of dynamic assertions, by means of the DONE 
operator, in order to express, in analogy with [7,8], performances actually (and 
not just possibly) taking place in a backward direction. 

3.1 Language 

The alphabet consists of a set P of propositional symbols (p), the proposi- 
tional constant V, the operator DONE, a set of agent identifiers / (groups 
of agents identifiers are denoted by a set A of atomic action sym- 

bols typically denoted by a (this set at least includes the coordination actions 
coordinate(ai, cti, Y) with G /), the doxastic operator B, and the dynamic op- 
erators [ ] and ( ) . The language £ is based on three types of syntactic constructs 
that we are now going to define. 

The set Act of action expressions (a) is defined through the following BNF: 
a ::= a \ skip \ a \ a\ + a 2 \ a±Sza 2 | a i; a 2 . 
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where skip represents a “doing nothing” action, t stands for the negation oper- 
ator, + stands for the indeterministic choice operator, & for the parallel perfor- 
mance operator and ; for the sequencing operator. The set Evt of event expres- 
sions (£) is defined through the following BNF: 

£ :; = X : a \ X : a |£i + £ 2 | £l &£2 | £ 1 ; £ 2 - 

Notice that the same notation for actions and event operators (negation, +, &, ;) 
is used. It is nevertheless obvious that they belong to different categories of 
operators. We chose, however, for keeping notation not too rich. 

The set Ass of assertions (<j>) is defined through the following BNF: 

0 ::= V I V | DONE{£) \ -><j) \ <f>i V fa \ <j)i A fa \ <j*i —> <f>2 \ [£]</> I Brf. 

3.2 Models 

In order to give a semantics to the language introduced above we start defining 
the notion of model for C. 

Definition 3. (Models) A model M is defined as follows: 

M = (V + (I) , A U skip, W , [[ ]]k, {Mj}, e i, — <, 7r) 

where: 

— 7 ?+ (I) is the non-empty powerset of the finite set of actors I, that means the 
possible groups of actors. We assume I = I. 

— A U skip is the set of actions. 

— W is the set of possible states. 

]]fl is a function f s.t. f : Evt x W — > ^(W), to each event expression- 
world couple it associates the set of states to which the performance of that 
event in that world leads. It consists of a composition of the two functions 
]] and R which will be introduced in Section 3.3. 

— {Rj}jgn is a family of serial symmetric and transitive accessibility relations 
which are indexed by actors indicating the believable worlds of agent ai 4 . 

— -< is a partial ordering on W denoting the order in which worlds are reached 
through actual performances of events. This ordering is constrained as fol- 
lows: if W\ -< w 2 and3w3 s.t. wsHkiUi oru^lhu^ thenwfM^iW'i andwfSliWi . 
From an intuitive point of view, this condition guarantees the whole path of 
actual performances through W to be doxastically accessible. 

— j t is a usual truth function f s.t. f : Ass x W — > {1)0}. 

Like in [9, 6, 7] our semantics consists of two parts: first event expressions are 
interpreted as set theoretic constructs on A where events get a so-called open 
interpretation; successively event expressions are interpreted as state-transition 
functions determining the accessibility relation [[ ]]/j on W. 

4 The doxastic part of the framework will be of interest in particular for the modelling 
of an example in Section 4. 

5 This condition is important for proving validity (10) in Proposition 1. 
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3.3 Synchronicity Sets, Steps, Synchronicity Traces, and Worlds 

The interpretation of events is based on the basic notion of synchronicity set 
(s-set). 

Definition 4. (s-set) The set S of s-sets is defined as follows: S = V + (I) x 
{skip} U V + (I) x V+( A). 

Synchronicity sets, that is elements of S, are denoted by Si, S 2 , Informally, 

a s-set is nothing but a set of parallel executions of events by a group of agents, 
and formalizes the aforementioned open interpretation view on events. Based on 
the notion of s-set we define the notion of step 5 . 

Definition 5. (Step) The set Step of steps is defined as follows: 

Step = {x X er+(i)Sx | VX, Y £ V + (I) :Y CX => act{S Y ) C act{S x ) & 
MX,Y £ V + ( I) : act(Sy) = skip => act(S x uy) = act(S x )} 

where act is a function that extracts the action component from a given s-set 
(act(X : {a 1 ,a 2 }) = {ai,a 2 }J. 

Steps represent a sort of snapshot of the activity of each subgroup of I at a certain 
moment, depicting how all agents move one “step” ahead. Steps are therefore 
sets of s-sets of cardinality 2 n — 1 where n is the number of agents in I. They are 
constrained in such a way that whatever action is performed by a subgroup is 
also performed by a supergroup, and subgroups remaining inactive are treated 
as performing a skip action. Steps, that is elements of Step, are denoted by 
Si, s 2 , . . .. 

In order to provide a semantics for sequential expressions the concept of 
synchronicity trace (s-trace) is needed. Notice that this concept uses steps instead 
of s-sets like in [9, 6]. 

Definition 6. (s-trace) The set T of s-traces is defined as follows: 

Y — {(si , .. ., s n ,...) | si , ..., s n , .. . £ <S} . 

The length of an s-trace t is denoted by durit). We assume durit) to be finite. 

An event will be interpreted as a set of s-traces. The range for our inter- 
pretation of events is a set £ such that £ = Y(T). Elements of £ (sets of s- 
traces) are denoted as T\,T 2 , . . . The length dur(T) of a set T is defined as 
max{dur(t)\t € T}. 

We can now introduce the operations that constitute the semantic counter- 
part of our syntactic operators. 

Definition 7. (Operations on events) Let T\,T 2 £ T: 



T\ o T 2 — {ti o t 2 | ti £ Ti, t 2 £ T 2 } 

Notice that in [7] s-sets are called steps, and no notion of step as it will be defined 
in this work occurs there. 
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T\ Ifi) T 2 — | J{i 1 Ifil t 2 | t\ £ T\, t 2 £ I2} 

T\ IUI T 2 = T\ U T 2 ~ (| J{^i Ifil £2 | ti £ Ti, t 2 £ T 2 and t\ f 2 }) 

f = f if T ± 0, f = (fil{S | a £ T} 

\ if T = 0, f = Step 

Where: 

— ti o f 2 is defined as follows: if t\ = ( ) and t 2 = (s}, ..., s(„) f/ien, 
fl 0 t-2 (Si , S n , Si , • ••, S m ) . 

{ ti */ 0 £ startftf) 
t 2 if t\ £ start(t 2 ) 

0 otherwise 

where start is a function which associates to a given s-trace all its starting 
possible s-traces: startft ) = {t' \ t! =t or 3 1" ^ 0 s.t. t' o t" — t}. 

— t is defined as follows: t = Ui < n <dur(t) ( s i> ■ where s = Step — {s} 7 . 

Intuitively, we want HU to yield the property: a = a + a\b for event expressions. 
In order to establish this property we cannot just use a union of the sets of s- 
traces representing a and a; b but have to do some “cleaning up” by subtracting 
superfluous parts. 

The semantics of events are obtained by means of a function [ ] : Evt — > £ 
such that: 

Definition 8. (Semantics of events) 

[[X : a ]] = (s | S x £ s,a€ act(S x )} 

Ki;6]]= Ki]]° [&]] 

Ki + 6B = Ki]]w [fe]] 

]] = Ki ]] ini [[6 ]] 

KB = KB 

U skip ]] = {skip}. 

The basic clause stipulates that the meaning of an atomic event consists of the 
set of steps where that action at least is performed by that specific group of 
agents. 

On the basis of this evaluation for events, an evaluation of groups performing 
complex actions is obtained: 

Definition 9. (Semantics of collective actions) 

pf:a i; a 2 ]]= [[X : m ]] o [[X : a 2 ]] 

[[X : ar + a 2 B = [[X : m ]] HU [[X : a 2 ]] 

[[X : a 1 &a 2 ]] = [[X : aq ]] Ifil [[X : a 2 ]] 

[[XXcd]]= [[XTa 7 ]]. 

7 Negation of sequences constitutes a delicate matter. For a deeper discussion of this 
issue we refer to [6]. 
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To connect this interpretation of events to a possible world semantics a func- 
tion R : £ x W — > W is defined, which couples events with state-transitions. 

Definition 10. (Function R) 

R{T,w i) = {w 2 | 3 1 € T s.t. w 2 = R(t, rtq)} where R on transitions is 
inductively defined as follows: 

R(si,wi) = r(si,w\) 

R(ti o t 2 , u>i) = R(t 2 , R(h,wi)). 

and r : S x W — > W, that is a function that, given a state, returns the following 
state reachable through a given synchronicity set, and such that r({skip}, w) = w. 

3.4 Evaluating Formulas 

The meaning of formulas <f> in a world w, given the structure M, is defined as 
usual. For space reasons we report here only clauses for dynamic operators, and 
the DONE unary operator. 

Definition 11. (Semantics of assertions) In the following letdur( [£i ]) = 1, 
M,w i |= [£](/> iff \/w 2 G [£ ]] r (w 1 ),M,w 2 |= cj) 

M,w 1 |= iff 3 w 2 G [[£ Ir(w 1 ),M,w 2 1= </> 

M,w i |= DONE(^i) iff \/w 2 G W, w 2 -< u>i => wi G [[Ci lflW 2 ; 

M,w i |= OOJVf?((; (i) iff \/w 2 G W, w 2 -< w± =$■ M,w i (= DONE(^\) and 
M,w 2 h DONE(C). 

Informally, a sentence [£](/> ((^) </>) is true in w iff 4> is true in every world (re- 
spectively in at least one world) accessible through a performance of £. As to 
the semantics of DONE(t;), the two clauses should be read as a basis and an 
induction step: intuitively, a sentence DONE(tf) is evaluated as true in a world 
w i iff that world can be reached via a sequence of events of length one from all 
the worlds w 2 which are connected with w\ along the -< ordering. 

We do not provide a separate semantics for the coordination actions. Instead 
we give the following constraint on the possible models which indicates that the 
effect of a coordination action is a certain type of belief in the recipients of that 
action. 

Definition 12. (Coordination action) Let aj G I with 1 < j < n and n = 

||I||, then: 

M,wi \= DONE{{a\} : ot\) => \/w 2 G [[{aj} : coordinate^, a±, Y) ]]_r(wi) : 
M,w 2 (= /\ B J {DONE{a 1 : aq)) 

aj dY 

We deem worth stressing that the constraint above determines only a kind of 
minimal characterization of a notion of coordination, which is based on the in- 
formal discussion of Section 2.2. 

The deontic notions, which range over events, are defined according to the 
following reduction principles: 
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Definition 13 . (Deontic notions) 

m = [O'; 

0(0 = 

p ( 0 = -’K]v. 

For an extensive account of how these notions are related we refer to [12]. In what 
follows our attention is exclusively focused on expressions concerning obligations. 



3.5 Some Relevant Validities 

We will now focus on some validities that are relevant in order to model the col- 
lective obligations appropriately. The validities listed below are of three kinds: 
validities (2)-(9) show how obligations propagate within the group, that is how 
the sub/ supergroup relation is connected with the enactment of a group obli- 
gation and in particular how the obligation on a plan distributes over the obli- 
gations on the single components of that plan; second, validity (10) has to do 
with the beliefs of each individual agent about the task allocation and related 
obligations addressed to him; third, validities (11)-(13) are of a more general 
kind, and express some very basic features of the framework. 

Proposition 1 . (Validities) Let X,Y G P + (I) and 01,0:2,71,72 G Act and 



71,72 do not contain any occurrence of the action negation symbol: 

1= 0(X U Y : tT) -4 0(X : 7) (2) 

f= 0(X : 7) -> (V U Y : 7) (3) 

|= 0(X : 7i + V : 71) — t 0(X D Y : 7!), with Inh/0 (4) 

1= 0(X : 71 + Y : 71) -> (X U Y : 7) (5) 

[= 0(X : 71 & Y : 72) — > ( X (~l Y : 71&72), with X D Y yf 0 (6) 

1= 0(X : 71 & Y : 72) -> (X U Y : 71&72) (7) 

|= 0(X : 71 ; Y : 72) — t 0(X U Y : 71572) (8) 

\= 0(X : oi & Y : a 2 ) O 0(X : oi) A 0(Y : o 2 ) (9) 

|= Bi{0({j} : oi ; {«} : o 2 )) -t Bi(DONE({j} : oi) -t 0({i} : o 2 )) (10) 

(= 0(X : oi ; Y : o 2 ) 0(X : Oi) A [X : oi ]0(Y : a 2 ) (11) 

)= 0(X : a 1) V 0(Y : a 2 ) -> 0(X : a ± + Y : o 2 ) (12) 

\= [X : oi }DONE(X : oi). (13) 



Proofs are omitted but can be easily obtained from the semantics presented. 
Nevertheless, some of these validities deserve some remarks. We start from (10), 
which shows that, given a (possibly limited) knowledge of the strategy of the 
group, that is, of a task allocation sequence, and given the knowledge of what 
just happened, an individual agent is aware of the obligations stemming from 
that task allocation and addressed to him. This validity is in some sense central 
for both coordination and knowledge problems raised in the Introduction and in 
Section 2. 
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Other interesting validities are (3) and (8), showing how each action of a 
subgroup is also an action of a supergroup (this manifests exactly the constraints 
contained in Definition 5). To get from the action of a supergroup to the ones 
of the subgroups is a more complicated matter. Highly desirable in this sense 
would be the following property: 

h 0(X : 71172) -»• 0((X ii : 7l ); (X 12 : 72 ) + ... + (X nl : 7l ); (X n2 : 72 )) (14) 
where : X ,\ , X; l2 C X, and 1 < i < n 

with n = \\V + (X) x V + {X)\\ 

This formula says that the obligation to execute a (possibly partial) plan, ad- 
dressed to a group, implies the obligation to choose to perform at least one 
among all the task allocations, which are possible given that group of agents 
and that plan. Such a formula is valid under precise conditions. Note first of all 
that, given the properties of the IUJ operation (Definition 7), it does not hold in 
general that if Ti C T 2 then T 2 = Ti HU T 2 . Let us now consider a <g relation on 
sets of s-traces defined as follows: Tf <£ T 2 iff 1. Ti C T 2 and 2. \/t 3 G T 2 /Ti, 
$ti G T\ s.t. t\ G start(t 3 ) 8 , that is to say that T\ is not sequentially extended 
by T 2 . Intuitively, T\ <e T 2 iff T\ and T 2 are in a subset relation and the ele- 
ments belonging to T 2 but not to T\ are not sequences obtained concatenating 
new s-traces to elements of T\ . Considering the <s relation, the following can be 
proved: 

Proposition 2. (Choice on task allocations) 

If Vi s.t. 1 < i < n and Xu,X i2 C X, [[Xu : 7l ]] o [[X, ;2 : 72 ]] is not 
sequentially extended by [[X : 7l ]] o [[X : 72 ]], with n = \\P + {X ) x V + {X)\\, 
then: 

|= 0{X : 7l ; 72 ) -»• 0((X u : 7 i); (X 12 : l2 ) + ... + {X nl : 7l ); {X n2 : 72 )). 

Proof. Formula (14) follows from two facts: 1) on the ground of Definitions 5 and 
7, for each element Xu , Xi 2 we have that [Xu ■ 71 ]° l x i2 ■ 72 ] C [X : 7 i ]o [X : 
72 ]; 2) from Definition 7, holding that VTi, T 2 s.t. Ti <g T 2 , T 2 = T\^T 2 we obtain 
that: [X : 7l ]o [X : 72 ] = [In : 7 i ]o [X 12 : 72 ]iyj...iyj [X nl : 7i ]o [X n2 : y 2 ], 
since 3 j s.t. 1 < j < n and Xji = Xj 2 = X. ■ 

Despite its complex formulation this property states indeed something re- 
markably intuitive: (14) holds whenever within a given group each action per- 
formed by a subgroup is always “complete” from a sequential point of view 
in the sense that no supergroup performs any action which contains an action 
performed by the subgroup as a starting action (sequence). 

4 Collective Obligations and Coordination as Action: 
Modeling an Example 

In this section we will now show the use of the formalism developed in the 
previous section to model a collective obligation and show how we can use the 



See Definition 7. 
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validities to derive some individual obligations. We need the properties of the 
coordinating actions to also make all agents aware of their obligations at the 
right moment. 

Let us consider again the example we have several times touched upon. We 
have the program committee PC of the DEON’04 workshop, with a chairman c, 
and the other members aj, . . . , a n , such that PC = {c, a±, . . . , a n }. The collective 
obligation of the program committee is to notify the authors of the acceptance 
of their papers: 0(PC : notify). It seems reasonable to consider the constraint 
contained in Proposition 2, which enables formula (14), to be met by the example 
at issue (each agent perform a sequentially “complete” action) , and therefore to 
be able to infer from 0(PC : notify) an obligation on the choice among all the 
possible task allocations. Let us then suppose that the program committee has 
selected, out of that choice, the following plan for the notification of acceptance: 
the chairman collects the submitted papers and divides the papers among the 
other PC members; the PC members review the papers they have received from 
the chairman and send their results to the chairman; the chairman makes the 
final decision which papers are selected for the workshop and informs the authors 
about the decision. Including the coordination aspect this corresponds with the 
following task allocation CP, which belongs to the set PPlan(PC : notify) 9 : 

CP = ( {c} : collect ; {c} : coordinate^, collect, {c}) ; {c} : divide ; 

{c} : coordinate^, divide, {ai, ..., a n }) ; 

({ai} : reviewi; coordinate(ai, reviewi, {c})) 

& ... & ({a„} : review n ; coordinate(a n , review n , {c})) ; 

{c} : decide ; {c} : coordinate (c, decide, {c}) ; {c} : inform, authors) 

where skip can be substituted for coordinate^, a, {c}). Given the collective obli- 
gation 0(G : write) and the more concrete obligation on the task allocation 
sequence CP many consequences, which we here omit for space reasons, can be 
drawn through validities (2)-(13). 

We can now also come back to the question who is taking the initiative for 
the coordination action. If it is the agent that also performed the action (as 
in the example above) the coordination becomes an informative action. If the 
initiative lays with the other party it becomes a checking action. The difference 
between these two kinds of coordination actions is very important for the issue 
of responsibility. In the example, the chairman has to inform the other mem- 
bers that he has divided the papers among them. If a member of the PC has 
not received any paper to review and got no information of the chairman, the 
chairman is responsible for the violation of the obligation that some papers are 
not reviewed. If the coordination action, however, is defined as a checking ac- 
tion: A : coordinate^, divide, A), then all the members of the PC have to check 
whether the chairman has divided the papers, and are therefore also responsible 
if e.g. the chairman has forgotten to send a member the papers to be reviewed. 
So, the question who is responsible for a certain action depends on the coor- 
dination actions. In a structured group, for example in a formal organization, 

9 See Definitions 1 and 2. 
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the coordination can be defined explicitly and therefore also the responsibilities. 
This is especially necessary, if not everyone in the group has knowledge about 
the complete plan. In a group which is not so structured it is imaginable that 
all the members of the group know the plan, and that the coordination consists 
of informing and checking. 

In this example we could assume that every member of the PC has knowledge 
of the complete plan, which implicitly has the consequence that a member who 
has not received papers from the chairman, has the obligation to check whether 
the chairman has done his task. In our formalization we could also indicate 
that only, e.g., two members a\ and 02 have to check whether everyone has 
received the papers by replacing of A : coordinate^, divide, A) by {01,02} : 
coordinate^, divide. A). Of course, it is now up to 01 and 02 to make sure that 
all the PC members know that they have received the papers and have the 
obligation to review them! 

Given the collective obligation 0 (PC : notify) and the more concrete obliga- 
tion on the task allocation sequence CP it is now possible to check all kinds of 
properties of the plan, a certain knowledge about the plan and a coordination 
scheme with the plan. It becomes possible to check whether all agents know that 
they have an obligation whenever they have one (true in the example above). 
Whether all agents know whenever another agent violated his obligation (not 
true in the example). Whether the coordination is the most efficient possible, 
given a certain knowledge of the agents (and maybe observable actions), etc. 
Due to space limitations we omit these discussions in the present paper. 

5 Discussion and Conclusions 

Before summarizing the contributions of this work and showing some possible 
lines of development, it is worth adding a few remarks about the role the notions 
of plan and allocation come to play in our approach. We stated that a plan is a 
way of performing a complex action, and that a task allocation determines who 
in a group carries out which part of the plan. The problem of how a plan and an 
allocation are chosen, that is, how they can be selected among all the possible 
ones, has been disregarded. We chose to do that basically for two reasons. 

— Firstly, because our central concern is to understand what are the formal 
properties of obligations distribution within groups, and not how this distri- 
bution can be generated. 

— Secondly, because the ways plans and allocations might be selected (that is, 
how they are established) are several and can obey different requirements: 
it might be required that plans are such that each agent is capable of per- 
forming the task he is appointed to (and this is indeed a requirement we 
assumed); or it might be required that each task assignment is “morally 
acceptable” for each agent and should not conflict with the general deon- 
tic principles each agent might be endowed with; besides, plans might be 
required to be of a “best choice” kind and provide optimal solutions, etc. 
Several are also the effective sources of these plans and allocations (that 
is, who establishes them): they might be hard-coded by a “designer” in the 
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group, or emerge from specific power relations holding within the group itself 
(see [2]), or from individual commitments of the agents (like in [3,4]), or be 
the result of delegation mechanisms (see [2]), etc. 

Following these remarks, some further words can be spent, in particular with 
respect to the concept of delegation. Notice that the example of the program 
committee of DEON’04 can be easily analyzed also in terms of a notion of del- 
egation: the program committee chair, being obliged to review all submitted 
papers, delegates reviews to the committee members. In this reading of the ex- 
ample no notion of collective agency and obligation is involved. However, such 
an approach seems to be less general, it presupposing the existence of a starting 
individual obligation (which is not always available) , and of a delegation mech- 
anism. Examples of obligations addressed exclusively to groups can be easily 
devised and are indeed discussed in the literature (e.g. a mother ordering her 
two sons to set the table [14, 3]). In those cases no analysis in terms of individual 
obligations and delegation is feasible, while the approach proposed here remains 
applicable. The theoretical point that should be stressed is that the effect of a 
delegation process consists exactly in the establishment of a precise task alloca- 
tion for the group: when the program committee chair delegates reviews to the 
members of the program committee, he establishes a precise task allocation, and 
therefore a determined distribution of obligations within the program committee 
itself. For these reasons, the formal analysis of obligations distribution, given a 
task allocation, seemed to us to constitute a more primitive issue. 

Such a logical theory of collective obligation has to face many complex and 
interesting questions: 

From the point of view of methodological individualism, the action of 
a collective is in some sense composed of or determined by individual 
actions performed by the members of the collective. The general study 
of the nature of that composition, of the dependence of collective actions 
on individual ones, could be said to constitute the theory of collective 
action in a narrower sense. ([11]) 

A first attempt is made to “constitute the theory of collective action in a nar- 
rower sense” by the introduction of a plan (task allocation) and coordination. 
We discussed collective agency on the basis of some inputs from planning liter- 
ature in AI in order to provide some definitions of concepts of relevance for our 
analysis, especially coordination. The notion of coordination given a plan is very 
useful to determine which agent has to perform and which agent is responsible 
for a certain sub-action necessary for the fulfillment of the collective action. 

We provided a formal framework in which relevant notions for explaining 
collective agency can be formalized, such as task allocation, collective obligation, 
and coordination. This framework can help in representing coordination issues 
to indicate the individual responsibilities, though of a quite simple kind. We 
believe it provides a valuable basis for further research in collective obligations. 
First, it is our aim to embed in our framework a more comprehensive theory of 
responsibility. Secondly, we would like to consider more types of meta-actions. 
And finally we would like to check the influence of group structures on collective 
obligations. 




Collective Obligations and Agents: Who Gets the Blame? 145 



References 

1. J. Carmo and O. Pacheco. Deontic and Action Logics for Collective Agency and 
Roles. In R. Demolombe and R. Hilpinen, editors, Proc. Fifth International Work- 
shop on Deontic Logic in Computer Science (DEON’OO), pages 93-124. ONERA- 
DGA, 2000. 

2. C. Castelfranchi Modelling Social Action for AI Agents. In Artificial Intelligence, 
Volume 103, pp. 157 182, 1998. 

3. L. Cholvy, Ch. Garion Collective obligations, commitments and individual obliga- 
tions: a preliminary study In Proceedings of 6th international Workshop on Deontic 
Logic in Computer Science (DEON’02), London, May 2002. 

4. L. Cholvy, Ch. Garion Distribution of Goals Addressed to a Group of Agents. In 
Proc. of 2nd Int. Joint. Conf. on Autonomous Agents and Multi-Agents Systems 
(AAMAS 2003), Melbourne, July 2003. 

5. K. S. Decker and V. R. Lesser. Designing a Family of Coordination Algorithms. 
Technical Report No. 94-14, Department of Computer Science, University of Mas- 
sachussets, Amherst, MA01003, 1995. 

6. F. Dignum J.-J.Ch. Meyer. Negations of Transactions and Their Use in the Speci- 
fication of Dynamic and Deontic Integrity Constraints. In M. Kwiatkowska, M.W. 
Shields, and R.M. Thomas, editors, Semantics for Concurrency, Leicester 1990, 
pages 61-80, Springer- Verlag, Berlin, 1990. 

7. F. Dignum, J.-J.Ch. Meyer, R. Wieringa and R. Kuiper. A Modal Approach to In- 
tentions, Commitments and Obligations: Intention plus Commitment Yields Obli- 
gation. In M.A. Brown and J. Carmo, editors, Deontic Logic, Agency and Norma- 
tive Systems (Workshops in Computing), pages 80-97. Springer- Verlag, 1996. 

8. F. Dignum and B. van Linder. Modelling Social Agents: Communication as Action. 
In M. Wooldridge J. Muller and N. Jennings, editors, Intelligent Agents III (LNAI- 
1193), pages 205-218. Springer- Verlag, 1997. 

9. J.-J. Ch. Meyer. A Different Approach to Deontic Logic: Deontic Logic Viewed as 
a Variant of Dynamic Logic. In Notre Dame Journal of Formal Logic, Volume 29, 
pages 106-136, 1988. 

10. J.-J. Ch. Meyer and W. van der Hoek. Epistemic Logic for AI and Computer 
Science. CUP, 1995. 

11. I. Porn. The Logic of Power. Basil Blackwell, Oxford, 1970. 

12. L. Royakkers. Extending Deontic Logic for the Formalization of Legal Rules. Kluwer 
Academic Publishers, Dordrecht 1998. 

13. L. Royakkers and F. Dignum. Collective Obligation and Commitment. In Proceed- 
ings of 5th Int. conference on Law in the Information Society, Florence, December, 
1998. 

14. L. Royakkers and F. Dignum. No Organization without Obligations: How to For- 
malize collective obligation?. In M. Ibrahim, J. Kung and N. Revell, editors, Pro- 
ceedings of 11th International Conference on Databases and Expert Systems Ap- 
plications (LNCS-1873), pages 302-311. Springer- Verlag, 2000. 

15. S. Russell and P. Norvig. Artificial Intelligence. A Modem Approach. Prentice Hall 
International, 1995. 

16. M. Tambe and W. Zhang. Towards Flexible Teamwork in Persistent Teams: Ex- 
tended Report. Journal of Autonomous Agents and Multi- Agent Systems, 3(2): 159- 
183, 2000. 




Conflicting Imperatives 
and Dyadic Deontic Logic 



Jorg Hansen 



Institut fur Philosophie 
Universitat Leipzig 
Beethovenstrafie 15, D-04107 Leipzig 
jhansen@uni-leipzig.de 



Abstract. Often a set of imperatives or norms seems satisfiable from 
the outset, but conflicts arise when ways to fulfill all are ruled out by 
unfortunate circumstances. Semantic methods to handle normative con- 
flicts were devised by B. van Fraassen and J. F. Horty, but these are not 
sensitive to circumstances. The present paper extends these resolution 
mechanisms to circumstantial inputs, defines according dyadic deontic 
operators, and provides a sound and (weakly) complete axiomatic sys- 
tem for such a deontic semantics. 



1 The Question of Normative Conflicts 

Are there moral conflicts? The orthodox belief in the 1950’s was that such con- 
flicts only exist at first glance, the seemingly conflicting obligations arising from 
the application of merely incomplete principles. Instead, what is actually obliga- 
tory must be determined by careful moral deliberation that involves considering 
and weighing all relevant facts and reasons, and cannot produce conflicting out- 
comes 1 . Among the first that came to reject this view were E. J. Lemmon [18] 
and B. Williams [32]: Lemmon observed that in cases of true moral dilemma, 
one does not know the very facts needed to determine which obligation might 
outweigh the other. Williams argued in reductio that if, in case of conflicting 
oughts, there is just one thing one ‘actually’ ought to do, then feelings of regret 
about having not acted as one should have are out of place and one should not 
mind getting into similar situations again. To avoid having to accept the deriva- 
tion of the ought of a contradiction from two oughts with contradictory contents, 
Williams argued that deontic logic should give up the agglomeration principle 

(C) OA A OB -> 0(A A B) 

Lemmon had no such qualms: he advocated dropping the Kantian Principle 
‘ought implies can’ 

(KP) OA -* oA 

and concluded: 

1 W. D. Ross’ [22] prima facie obligations and R. M. Hare’s [10] ‘rules of thumb’ must 
be mentioned, though I cannot do these authors justice here. 



A. Lomuscio and D. Nute (Eds.): DEON 2004, LNAI 3065, pp. 146-164, 2004. 
(c) Springer- Verlag Berlin Heidelberg 2004 
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“I should like to see a proper discussion of the arguments that go to 
resolve moral dilemmas, because I do not believe that this is an area 
of total irrationality, though I do not believe that a traditional logical 
approach (the logic of imperatives, deontic logic, and whatnot) will do 
either.” 

Regarding commands and legal norms, G.H. von Wright ([29] clr.7), like H. 
Kelsen ([16] p.211) at the time, excluded the coexistence of conflicting norms 
from the same source: The giving of two conflicting norms is the expression of 
an irrational will; it is a performative self-contradiction and as such a pure fact 
that fails to create a norm. E. Stenius [25] and later C.E. Alchourron and E. 
Bulygin [3] rejected this view: A system of norms that is impossible to obey 
might be unreasonable and its norm-giver blameworthy, but its existence does 
not constitute a logical contradiction - conflicts are ubiquitous in systems of 
positive law and logic cannot deny this fact. In his later theory, von Wright [31] 
concedes that factual normative orders may or may not be contradiction-free, 
and reformulates deontic principles as meta-norms for consistent norm-giving. 
Kelsen [17] later came to view logic as inapplicable to law. 

2 Van Fraassen’s Proposal and Horty’s Variation 

2.1 Van Fraassen’s Operator O f 

Not taking sides, pro or contra the existence of genuine normative conflicts, but 
arguing that the view in favor seems at least tenable, B. van Fraassen [28] took 
up the burden of finding plausible logical semantics that could accommodate 
conflicting obligations. The intended semantics should accept the possible truth 
of two deontic sentences OA, 0~>A without committing the norm-subject to the 
absurd by making 0(AA->A) true, for van Fraassen wanted to keep the Kantian 
Principle. Given the existence of certain imperatives in force, i.e. imperatives that 
are left as valid, relevant, not overridden etc. by some unspecified deliberation 
process, van Fraassen’s idea was to make these imperatives part of the logical 
model, and to describe something as obligatory if it serves to satisfy some, not 
necessarily all, imperatives. Formally, let I be the set of imperatives in force, 
B be the set of possible states of affairs, and i + C B be the possible states of 
affairs where the imperative i £ I is considered fulfilled. Let ||A|| C B be the set 
of possible states of affairs where the indicative sentence A is considered true. 
Finally, let score(v) be the set of all imperatives that are fulfilled in the state of 
affairs v: score(v) = {i £ I | v £ i + }. Van Fraassen then defines 2 : 

[Df-F] O f A is true iff 3v £ ||A|| : W £ ||-u4|| : score(v) $£ score(v') 

So A is obligatory if and only if (iff) the falsity of A would commit us to a lower 
‘score’ than one which could be achieved when A is true. In other words, A is 
obligatory if the truth of A is necessary for achieving a maximal score. 

The definition given is van Fraassen’s final proposal in [28] p. 18. 



2 
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By slightly changing the viewpoint, van Fraassen’s proposal might also be 
described in the following way: Let I be a set not of imperatives, but of indicative 
sentences in the language Lbl of some basic logic BL. The motivation is that I 
contains one sentence A for each imperative i in force that is true in exactly those 
states of affairs in which the imperative is fulfilled, i.e. ||A|| = i + . BL is assumed 
to be compact and the turnstile in r \~bl A means a classical consequence 
relation that characterizes BL, r C Lbl, A £ Lbl- Let the remainder set hi i 
be the set of all maximal subsets that do not derive A, i.e. of all L' C L such 
that (i) F' F B l A, and (ii) there is no F" such that F' C F" C F and F" F A. 
Then Df-F is equivalent to Df-F*(/c means an arbitrary contradiction) 3 : 

[Df-F*] O f A is true iff 3F eILk: I' \~ BL A 

Accordingly, A is obligatory iff it is derivable from a maximally consistent subset 
of the imperative-corresponding sentences. 

To see how van Fraassen’s semantics work, first let I = {A,B}, where A, B 
are supposedly contingent and independent. There are no conflicts, I is consistent 
and O f A, O f B and O f (AaB) are all true since I derives A, B , A A B. Thus the 
semantics permit agglomeration of contents when the underlying imperatives do 
not conflict. For the conflict case, change / into {A AC, B A~>C}\ O f A and O f B 
are true since A and B derive from the maximally consistent sets {A A C} and 
{B A -iC}, but O f (C A ~>C) is false since no consistent subset derives C A ~>C. 
The same is true for O f (A A B) though {A A B} is consistent: the truth of A A B 
is not necessary for maximal norm satisfaction. 

An axiomatic system DF that is (weakly) complete with regard to van 
Fraassen’s semantics is defined by the following axiom-schemes, in addition to 
BL-instances and modus ponens (cf. [8] , t means an arbitrary tautology, and the 
index ‘F’ here and below indicates that the deontic operators occurring in the 
axiom scheme are thus indexed): 

(M f ) O f (AaB) -a (O f A A O f B) 

(D F ) -nO F k 
(N F ) o F t 

(Ext F ) If Lbl A -ca B then \~df O f A o O f B 

To van Fraassen’s own puzzlement, the cases where agglomeration remains per- 
missible seem not axiomatizable: object language does not reveal whether par- 
ticular A, B of some O f A, O f B are derived from the demands of imperatives 
that do not collide and so 0 F {A A B) should be supported 4 . 



3 Cf. Horty’s [13] Theorem 2. 

4 Agglomeration thus requires a consistency check of the underlying imperatives’ con- 
tents. As a solution, [26] and [27] have proposed a two-phase deontic logic, where 
‘consistent aggregation’ must take place before weakening of norm-contents. For 
consistency checks before agglomeration also cf. [14] and my [8] which provides a 
bimodal axiomatization. 
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2.2 The ‘Sceptical’ Operator O s 

The invalidation of the agglomeration principle by van Fraassen’s semantics did 
not make them popular (cf. [5] p. 298). Moreover, let a P F -operator for permis- 
sion be defined in the usual way, i.e. P F A is true iff ->O f ->A is true, and modify 
DF to additionally contain 

(Def F ) P F A o ^O f ^A 

Consider again I = {A A C, B A ->C}: O f {A A C) is true, and so is O f ~>C. Ap- 
plying (M f ) and (Ext F ), O f ~>(AaC) must be true, and by the above definition 
P F (A A C ) is false. So not even what is obligatory is always permitted, which 
was considered unintelligible [15]. 

In reaction to the dismissal of the agglomeration principle, Donagan [5] and 
Brink [4] have claimed that even if there could be a normative demand for A 
and a conflicting demand for B , with b bl A ^ ->B, it need not follow that 
the norm-subject have an obligation to realize A and an obligation to realize B. 
Rather, there should just be a disjunctive obligation to realize A or B. Given 
competing normative standards of equal weight, the strategy of this reasoning is 
not to trust a single standard, but to consider obligatory only what all standards 
demand. Let / be as before. Varying van Fraassen’s truth definition, Horty [13] 
has formalized this ‘skeptical’ ought as follows 5 : 

[Df-S] O s A is true iff VP £ I± k : V b BL A 

So O s A is true iff A is derivable from all maximally consistent subsets of I. 

Let again I = {A A C, B A ->C}. O s A and O s B are false and O s (A V B) is 
true: just AV B, but neither A nor B are derived by both of the two consistent 
subsets {A A C } and {B A ~<C}. P S (A A C) is also true: A , C were assumed to 
be contingent and independent, so the maximally consistent subset {A AC} C I 
does not derive ->(A A C). Ergo what is 0 F -obligatory is at least P s -permitted. 

A complete axiomatic system DS is defined by the axiom-schemes (Def s ), 
(M s ), (C s ), (D s ), (N s ), and (Ext 5 ), together with BL-instances and modus 
ponens. Since the truth definitions for O f A , P F A and O s A, P s A merely depend 
on the set / and BL, mixed expressions such as O f A A ~>O s A are meaningful 
and may be accepted as well- formed. Then 

(C FS ) O f AaO s B^O f (AaB) 

is valid, and the mixed system DFS - containing the axiom schemes for DF, DS, 
the axiom scheme (C FS ), all instances of BIMheorems and modus ponens - is 
sound and (weakly) complete (cf. [8]). 



5 More in parallel to van Fraassen’s original definition, one may equivalently define 
[Df-S*] O s A is true iff Vn £ || _, A|| : Av' £ ||A|| : score(v ) C score(v') 

The proof is easy and left as entertainment for the reader. 
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3 Predicaments and Dyadic Deontic Logic 

Arguing for the possibility of moral conflicts, R. Barcan Marcus [20] gave the 
following example: 

“Under the single principle of promise keeping, I might make two promises 
in all good faith and reason that they will not conflict, but then they 
do, as a result of circumstances that were unpredictable and beyond my 
control.” 

Note that there is no conflict at the outset: Any dilemma could have been averted 
by not promising anything. Moreover, there might have been some point in 
time at which keeping both promises was possible: Having 500 $ with me and 
another 1000 $ in the office, on Saturday I promise Sally and Jane 500 $ each 
with every intention of paying them on Monday, only to find out that the office 
had been burglarized over the weekend. Donagan [5] argues that this is not a 
genuine conflict, because three resolving principles apply: (i) one must not make 
promises one cannot or must not keep, (ii) all promises are made with the implicit 
condition that they are void if they cannot or must not be kept, (iii) one must 
not make promises when one does not believe that the other party has fully 
understood (ii). Now suppose whatever happens at the office, neither Sally nor 
Jane are going to let me off the hook, and I could have known this. According 
to (iii), I was wrong to make the promise, so am I entitled to break it? - We 
have here what G.H. von Wright terms a ‘predicament’: a situation from which 
there is no permitted way out, but to which there also is no permitted inlet (cf. 
[30] p. 78). The normative order is consistent, it is only through one’s own fault 
that one finds oneself in a predicament 6 . Von Wright then asks: 

“The man in a predicament will, of necessity, react in some way or other, 
either do something or remain passive. Even though every reaction of his 
will be a sin, is it not reasonable to think that there is yet something 
he ought to do rather than anything else? To deny this would be to 
admit that it makes, cleontically, no difference what he does. But is this 
reasonable? (...) If all our choices are between forbidden things, our duty 
is to choose the least bad thing.” 

Sub-ideal demands are usually represented by a dyadic deontic sentence 0(A/C), 
meaning that in case C is true it ought to be that A. By accepting all instances 

6 That predicaments only arise from an agent’s own faults, and not through misfor- 
tune or the wrongdoings of others, is a view von Wright and Donagan ascribe to 
Thomas Aquinas, but this does not seem quite correct: In the discussion of oaths 
( Summa Theologica II. II Qu. 89 art. 7 ad 2), Thomas considers the objection that 
it would sometimes be contrary to virtue, or an obstacle to it, if one were to fulfill 
what one has sworn to do - so oaths need not always be binding. In answering, 
Thomas distinguishes oaths that are unlawful from the outset, where a man sinned 
in swearing, and oaths that could be lawful at the outset but lead to an evil result 
through some new and unforeseen emergency: fulfillment of such oaths is unlawful. 
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of O(Aft) —> P(A/t) as a logical truth in [30], von Wright dismisses an in- 
consistent normative system as ‘conceptual absurdity’: if A is obligatory on 
tautological conditions (i.e. unconditionally obligatory), then there cannot be 
a likewise unconditional obligation to the contrary. But as far as I can see, von 
Wright does not similarly advocate excluding predicaments similarly on grounds 
of logic alone: 0{A/C) —> P(A/C) is not a theorem, so it remains possible that 
in circumstances C it ought to be that A and simultaneously it ought to be 
that ->A 7 . Dyadic operators are needed to express this different deontic-logical 
treatment of conflicts and predicaments, for otherwise it would be difficult to tell 
whether 0{C A) and 0(C —> ->A) are oughts that are conditional on C and 
so their contents may not be agglomerated, or oughts with material implications 
for contents that permit agglomeration. 

Turning object language oughts into a special sort of conditionals does not 
mean that there must be a change in the formalization of background imper- 
atives as well: Consider the set I = {{C A),{C — > — >^4)}, corresponding to 

background imperatives in the usual way. There is just one maximally consistent 
subset, which derives -> C, so O f -<C and O s ^C are both true. But there is no 
single standard available once C becomes true: the imperatives have not all been 
fulfilled (otherwise one would not be in condition C), and any maximal set of 
imperatives that is consistent with the given circumstances cannot contain all. 
So the proposal is to call A obligatory in case C iff, given the truth of C, A is 
necessary to fulfill as many norms as is still possible. Formally: 

[Df-DF] O f {A/C) iff 31' £ I±->C : V U {C} b BL A 

According to this definition, O f (A/C) is true iff there is some set, among the 
maximal subsets of I consistent with C, that together with C derives A. This is 
obviously a conservative extension of the definition given for the unconditional 
case, so we may define O f A =def O p (A/t). 

If a cautious, disjunctive approach were appropriate for cases of conflict, then 
it would be hard to see why predicaments should be treated differently: That 
conflicts must be accounted for at the outset, but analogues of Buridan’s ass 
cannot occur on the level of predicaments brought about by fate or unpredictable 
human nature, would hardly be plausible. Distrusting any single standard, such 
an approach would accept, given the circumstances C , only what is necessary by 
any standard that could still be met - no worrying about spilled milk. Formally: 

[Df-DS] O s (A/C) iff V/' e I±~>C : I' U {C} \~ B l A 

According to this definition, O s (A/C) is true iff all the maximal subsets of I 
consistent with C derive A , given the truth of C. This is again just a conservative 
extension of the unconditional case, so one may define 0 s A =def O s {A/t). 

In the remaining section, I give an axiomatic dyadic deontic system DDFS, 
and prove that this is sound and (only) weakly complete with respect to the 
above semantics. 



Cf. [30] pp. 36, 81, 89. 



7 
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4 The Dyadic Deontic Logic DDFS 

Let the basic logic be propositional logic: The alphabet has proposition letters 
Prop = {pi,P 2 , ■ ■■}, truth-functional operators ‘A’, ‘V’, F, and brackets 
The set of sentences is defined as usual. /\,\/ in front of a set of sentences 
means their conjunction and disjunction, and e.g. /\,- =1 T further abbreviates 
/\{Ai,...,A n }. In the semantics, valuation functions v : Prop — » {1,0} define 
the truth of sentences A £ Lpl as usual (written v 1= A), B is the set of all 
such valuations, and ||A|| means {u £ B | v 1= A}. PL is a sound and complete 
axiomatic system, and \~p F A means that A is provable in PL. 

The alphabet of the language Lddfs additionally has the operators ‘0 F ’, 
‘P F ’, l O s \ ‘ P s \ and the auxiliary ‘/’. Lddfs is then the smallest set such that 

a) for all A,C £ L pl , O f (A/C ), P F (A/C), O s (A/C), P S (A/C) £ L DD fs, 

b) if A, B £ L D dfs? so are ~~ , A, (A A B), A V B), (A—>B), {A o B). 

Outer brackets will mostly be omitted. For simplification we do not have mixed 
expressions and nested deontic operators as in p\/\O s {p 2 /pi), P S ( 0 F (p 2 /p 2 ) /pi)- 
For DDFS-semantics, the truth of DDFS-sentences is defined with respect 
to a set I C Lpl by the following clauses (Boolean operators being as usual) : 
I\=O f (A/C ) iff 3 1'£l±->C: I' U {C} \~ PL A 
I\=P F {A/C) iff VP G I±->C : ru {C}P PL ^A 
I\=O s (A/C) iff VP G I±->C : ru{C}L PL A 
I\=P S (A/C) iff 3P £ IL^C : ru{C}F PL ^A 
If I 1= A, A is called DDFS-satisfiable , and called DDFS-valid if I 1= A for all 
/ C Lpl (we write \=ddfs A). 

Consider the following axiom-schemes (* is the uniform index F or S): 

(DDef) 0*(A/C ) o ->P*(->A/C) 

(DM) 0*(AaB/C)^(0*(A/C)a0*(B/C)) 

(DC S ) O s (A/C) AO s (B/C) -a O s (AAB/C) 

(DC FS ) O f (A/C) A O s (B/C) -a O f (A A B/C) 

(CExt) If b p L C -A (A <*B) then L DDFS 0*(A/C) o 0*(B/C) 

(ExtC) If \- PL C ■£>■ D then L DDFS 0*{A/C) o 0*{A/D) 

(DN S ) O s (t/C ) 

(DN f ) If F pl -.C then L DDFS O p (t/C) 

(DD S ) If F pl -.C then h DDFS P s (t/C) 

(DD f ) P F {t/C) 

(Up) 0*(A/C A D) -a 0*(D -a A/C) 

(Downl) O f (A/C V D) A - O f (A A -> C/C V D) -a O f (A/C ) 

(Down2) O s (A/C V D) A -O f (A A -‘C/C VJ})a O s (A/C) 

(Down3) O s {A/C V D) A ~^O s {A A -‘C/C V D) -A O f {A/C ) 

(DDef), (DM), (DC) and (DC FS ) are the dyadic analogues of the monadic ax- 
iom schemes given above. (CExt) is a contextual ‘extensionality’ rule for conse- 
quents, and (ExtC) an extensionality rule for antecedents. A system that con- 
tains (CExt), (DDef) and 0*(t/C), P*{t/C) is inconsistent if C = k is allowed, 
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so (DN F ) and (DD S ) are accordingly restricted. (Up) transfers obligations con- 
ditionally from stronger to weaker circumstances, and (Downl-3) allow for corre- 
sponding transfers of obligations from weaker to stronger circumstances if these 
can be excluded to be ‘contrary-to-this-duty’. 

The axiomatic system DDFS is then the set such that (i) all LDDFS-instances 
of PDtautologies are in DDFS, (ii) all LpL-instances in the above axiom schemes 
are in DDFS, and (iii) DDFS is closed under modus ponens. If A € DDFS we 
write \~ddfs A and call A provable in DDFS. r C Lddfs is DDFS-inconsistent 
iff there are A 1> ...,A n in P, n > 1, with I ~ddfs (Ai A ... A A n ) — > k, otherwise 
r is DDFS- consistent. A £ Lddfs is DDFS- derivable from P C Lddfs (written 
r b ddfs A) iff P U {->A} is DDFS-inconsistent . 

Theorem 1. The following are DDFS-provable (* is F or S as indicated): 



(FH) 


0*(A/C V D) A P*(C/D) -a 0*(A/C) 


F 

+ 


S 


Mixed 
SFS, SSF 


(REF) 


0*(A/A) 


- 


+ 




(OR) 


0*(A/C) A 0*(A/D) -a 0*(A/C V D) 


- 


+ 


SFF, FSF 


(DR) 


0*(A/C V D) -a 0*(A/C) V 0*(A/D) 


+ 


- 


SFS, SSF 


(RM) 


0*(A/C) A P*(D/C) -A 0*(A/C AD) 


+ 


- 


SFS, SSF 


(CM) 


0*(A/C) A 0*(D/C) -A 0*(A/C A D) 


- 


+ 


FSF, SFF 


(CUT) 


Q*(A/C AD) A Q*(D/C) -A 0*(A/C) 


- 


+ 


FSF, SFF 



Proof. (FH) is the ‘down-theorem’ proposed in [6], it derives (Downl-3) given 
agglomeration, and the other theorems are well-known from the study of non- 
monotonic logics. All proofs are straightforward and I just give those for (FH) 
in version FFF and (RM) in version SFS; both will be employed below. 

(FH): (Downl) is O f (A/C V D) A -O f (A A ->C/C VD)a O f (A/C). By con- 
traposition O f (A/C\! D)A~<O f (A/C) -a O f (AA-iC/CV D). (DM) derives 
O f (AA^C/CVD) -► O^K/CVD), and (DD F ) derives P F (CVD/CVD), 
which using (DDef), (CExt), (ExtC) is equivalent to ^O f (~<C A^D/ DV C). 
O f (^C/C V D) A ^O f (^C A ->D/D VC) A O f (^C/D) is an instance of 
(Downl), so O f (A/CV D)A^O f (A/C) -a O f (~<C / D) is derived with modus 
ponens and PL, which is (FH) in contraposition. 

(RM): O s (d/(C'AD)VC)A-0 F (dA-(CAD)/(CAD)VC) -► O s (A/CAD) is 
an instance of (Down2). By use of (ExtC), 0 s (A/(C A D) V C) is equivalent 
to 0 s (A/C). By use of (DDef) and (ExtC) -0 F (iA-(CAD)/(CAD)VC) 
is equivalent to P F (A -A (C- AD)/ C) that derives from P F (C AD)/ C) with 
(CExt) and (DM), which derives from P F (D/C) with (CExt). Then (RM) 
is obtained by equivalent substitution and strengthening of the antecedent. 

Theorem 2. DDFS is sound. 

Proof. The validity of (DDef), (DM), (DC S ), (DC F ), (CExt), and (ExtC) is 
immediate. (DN S ), (DD F ) are valid since any subset of Lpl derives t, and any 
maximally consistent subset is consistent. If Ppl _, C I then at least 0 is in IL~>C, 
so IL-iC ^ 0 and (DN F ), (DD S ) are likewise true. Consider (Up), (Downl-3): 
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(Up) Assume O f (A/C A D ), so there is an /' G IL->(C A D) such that /' U 
{CAD} I ~PL A and /' U {<7} b pl D — y A. Since V Y'pl -i(C A D), also 
/' b pl ~<C, so by maximality there is an I" G /_l_-i(7 such that /' C /", so 
there is an I" G I-L~>C : I" U {C} bpp D — > A, so O f (D — » A/C). Assume 
O s (A/C A D). So for all /' G /_L-.(<7 A D) : /' U {C A D} b F p A. Suppose 
there is an /" G I±->C : /"U{(7} bpp D — > A. So also /"U{(7} bpp ->D and 
I" bpp -i(C A D). So by maximality there is an I' G I-L~>(C A D) : I" C V . 
Since /'bpp _, (C A D), I' Fpl ~>C, there is an I" G I±-->C : /' C /", so by 
maximality of each I" G IF~>C, /' = I". So there is an /' G /_L-i((7 A /)) : 
/'U{(7A/)}bpp A, which violates the assumption. So for all I" G IF~>C : 
/" U {<7} bpp D A, and O s (D -> A/C). 

(Downl) Assume O f (A/CV D), so 31' G /-L-i((7V D) : /'U{CVd} bpp A, and 
nO F (AAnC/CvD), so V/" G /l-.(C'VD) : /"U{CVH}b P p AA-<7. So 
I' ^PL -O. So by maximality 31"' G IF^C : /' C /"', so /'" U {<7 V L>} b PL 
A, so /'" U {(7} bpp A, so O f (A/C) is true. 

(Down2) Assume O s {A/C V D), so V/' G /J_-i(<7 V D) : /' U {C V D} bpp A, 
and ->O f (AA~<C/C\/ D), so V/' G Il-(CVd) : /'U{CVH}b P p AA-C. 
Suppose I" G /U-iC, so /"bpp — iC and /"bpp -i((7V D), so by maximality 
3/"' G /_L^(C'VD) : /" C /"'. By the first assumption /'"U{<7V.D} bpp A. If 
/"UjCV//} bpp A then 3{U, —An} Q /"' '■ {h, /" by compactness 
of PL. By maximality /" U {*i, bpp -i(7, but /" U {*i, C I'", 

so /'" U {(7 V £>} bpp A A -iC, which violates the second assumption. So 
I" UjdVfl} bpp A, /" U {<7} bpp A, and V/" G I±->C : /" U {<7} b F p A 
since I" was arbitrary, so O s {A/C) is true. 

(Down3) Assume O s (A/CVL), so VP G /l-i(CVD) : /'U{CVD} bpp A, and 
M7 S (A A -.C7/C V D), so 3/" G /_L-(<7 V D) : /" U {C V D} b PL A A ->C. So 
I" bpp -nC. So by maximality 31'" G I±->C : I" C /"', so /'"U{CVL} b P p 
A, so /'" U {(7} bpp A, so O f (A/C) is true. 

Theorem 3. DDFS-semantics are not compact. 

Proof. In [8] I provide a counterexample to the compactness of semantics that 
just employ the monadic cleontic operator O f . Since O f A can be defined as 
0 F {A/t), this also refutes compactness of DDFS and of the subsystem that 
contains just the dyadic operators O f and P F . The following counterexample is 
expressed in terms of the dyadic operators O s and P s only, which also refutes 
compactness of the subsystem that contains just these operators: Let 

r = {o s ( P2 /t)} 

u {P s hP 2 / P i)} u UZ 3 {o s ( Pi /pi)} 

U {P s Zp 2 /^Pi)} u {JZ 3 {0 S {PihPi)} 

U {P S {-^P2/Pl <Ap 2 )} U UZ3{° S (Pi/Pl ^p 2 )} 

U {P s Zp 2 /Pi j 2 )} U \J™ 3 { oS (Pi/Pi ^ ~^P2)} 

r is finitely DDFS-satisfiable: Let n be the greatest index of any proposition 
letter occurring in some finite //CL Then // = { p n +iA(pi -A - 1 P 2 ) , ~^Pn + iA 
{-'Pl -A -‘P 2 ) , P2,P3,—,Pn} satisfies r f . 
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For easy verification, I list the relevant sets of maximal subsets: 

f {p n+ 1 A Oi -+ “'P 2 ),P 2 ,P 3 , ••• ,Pn )}, 1 

1 {-■ 'Pn+1 A (->. Pi ~+ p 2 ),P2,P3 , - ;Pn )} j 

f {p„+l A {pi -+ ~^p 2 ),p 3 , ••• ,Pn )}, 

1 {“'Pn + 1 A (^Pl -+ ^P2),P2,P3, ••vPn)} 
f { Pn+1 A (Pi -f -^2), P2,P3, • • ■ i Pn) }, 1 
1 { “'Pn+1 A (^Pl -+ ->p 2 ), p 3 , • • • , Pn ) } j 

However, r is not DDFS-satisfiable: Suppose I C Lpl satisfies P , and let A G 
{Pi 7 - , Pi,Pi P 2 , Pi -‘Pi}- Observe that 

(i) There are I\,I 2 G I-L k such that Ii b PP p 4 A pi, I 2 b PP ->pi A Pi, i > 2. 
Proof : From O s (p 2 /t), P s (~>p 2 /->pi) G r and the validity of (Down2) it 
follows that there is an I\ G PL /c : I\ b PP p\. Likewise from O s (p 2 /t), 
P S (~'Pi/Pi) G r it follows that there is an I 2 G /_L k : I 2 b PP -ipi. To 
satisfy O s (p 2 /t) it is necessary that all I' G /_Lfc : I' b PP p 2 , and from 
O s (pi/pi), O s (pi/~>pi) G r and the validity of (Up), (DC S ) one obtains 
that for all P G PL fc : V b PP p it i > 3. 

(ii) For each A, there is an I A G PL-iA : I a U {A} \- PL ->p 2 . 

Proof: Let A G {pi,pi ++ p 2 }. Then by observation (i) I\ G PL-iA. Since 
h b PP p 2 , to satisfy P s (~>p 2 /A) G r there is an Ia G I-L~<A such that 
I A U/i b pl -1 A. So I a U{A} b pl ->(piAp 2 A...Ap n ) for some n. If n > 3 then 
I A U {A} b PL ->(pi A p 2 A ... A p n _ 1 ), since I A U {A} b Pi p n is necessary 
for O s ( Pn /A) G r. So I A U {A} bpL -'(pi A p 2 ), so Ia U {A} b PP -1 p 2 . 
Likewise, the proof for A G {“’PpPi ++ -‘Pi} is obtained from / 2 G PL-iA. 

(iii) If A G {pi,pi ++ ->p 2 } then I A U {pi,“ip 2 ,P3,P4, ■••} b PL k. If A G 
{^Pi,Pi P 2 } then I a U { ‘Pi , —‘Pit P3> P4? •■•} P pl k. 

Proof: Suppose A G {pi,pi ++ ->p 2 } and I A U |p 1 ,-'P 2 ,p 3 ,P 4 , •••} b PL k. 
Then T^UjA, -‘Pi,P 3 ,Pi, •■•} b PL k. So /+U{A} b PP -.(-.p 2 Ap 3 Ap 4 A...Apn) 
for some n. But also I a ^{A} b PL -ip 2 Ap 3 Ap 4 A... Ap n by observation (ii) 
and from the fact that / satisfies O s (pi/A) G P, 3 < i < n. So I A b PP ->A, 
but this contradicts I A G 7-L-iA. The proof for A G { — >p 1 , p-| ++ p 2 } and 
the set I a U {— >pi , -'Pi,P 3 ,P 4 , ■■■} is done likewise. 



I f ±k = 

IfP-'Pi 

If - -L-i(pi ++ p 2 ) 

//Tpi = 
7/T-i(pr ++ -ip 2 ) 



It follows that / Pl UJ( pi< _ > -,p 2 ) P pl k and i-, Pl UJ(p 1++ p 2 ) b PP fc. This is most easily 
seen by appealing to PPsemantics: some v G B satisfies {p 4 , -ip 2 ,p 3 ,p 4 , •••} and 
by (iii) all elements of I Pl as well as all of I( Pl **-, P2 ), so their union is satisfiable 
and therefore consistent (likewise for {-ipi, “ , p 2 ,P 3 ,p 4 , •■•} and P Pl U I( Pl ^ P2 ))- 
From (ii) it follows that 

Ip 1 U I( Pl ^ P2 ) b p L (pi -t -‘Pi) A ((pi ++ -ip 2 ) -+ -ip 2 ) 

I^P 1 U I( Pl ++ P2 ) b PL (-ipi -+ -■p 2 ) A ((pi ++ p 2 ) -+ -ip 2 ) 

But the conclusions are tautologically equivalent to -ip 2 , so there are consistent 
subsets of / that derive -ip 2 , and I P O s (p 2 /t ), although O s {p 2 /t) G P. 
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Theorem 4. DDFS is weakly complete. 

Proof. We must prove that if ^=ddfs A then \~ddfs A for any A £ L pl . We 
assume Fddfs A so —>A is DDFS- consistent. We build a disjunctive normal 
form of -i A and eliminate all negation signs in front of deontic operators by use 
of (DDef). The result is a disjunction of conjunctions, where each conjunct is 
either O f (B/C), O s (B/C), P F (B/C), or P S {B/C). One disjunct must then 
be DDFS-consistent. Let 8 be that disjunct. Let Lp L be the P-Psentences that 
contain only proposition letters occurring in 8. Let r(Lp L ) be a set of 2 2 mutu- 
ally non-equivalent representatives of Lp L , where n is the number of proposition 
letters in <5. By writing PPsentences (including t and k) we now mean their 
unique representatives in r(Lp L ). We construct a set A such that: 

(a) Any conjunct of 8 is in A. 

(b) For all B,C £ r(Lp L ): 

— either P F (B/C) or O f (~<B/C) £ A, and 

- either P S (B/C) or O s (^B/C) £ A. 

(c) A is DDFS-consistent. 

It then suffices to find a set I C Lp P that satisfies all B £ V. The proof fol- 
lows the completeness proof of Spolrn [24] for B. Hansson’s [9] preference-based 
dyadic deontic logic DSDL3 , and I will remark on the parallels as they arise. 

Definition 1. For any C £ r(Lp L ), let 

~ O s c = A{A £ r(L* L ) I O s (A/C) £ A}, 

— ©g = min {A £ r(Lp L ) | 0 F (A/C) £ A}. 

where minT = {A £ P | VP £ P, if \~pl B — t A then b A}, P C Lpl- 

We have O s (t/C) £ A due to (DN S ) and DDFS- consistency of A, so Oq is well 
defined for any C. From the definitions of A, Of,, and O f , we obtain: 

(LI) O s (A/C) £ A iff \~pl Of, — > A 

(L2) 0 F (A/C) £ A iff 30 c £ Og : h PL O c -t A 

Remark 1. Definition 1 identifies syntactically what Hansson called the deontic 
basis (Spohn [24] writes C) in an extension ||C||. Monadic deontic logic has just 
one basis, dyadic deontic logic usually has one basis for any C, and here there may 
be several bases Oq £ ©g which expresses some conflict or predicament in case 
C. Semantically, we want to identify ||0cj| with the set of ‘best’ states of affairs in 
He'll, where the particular standard can be made explicit here as the satisfaction 
of some maximum of imperative-corresponding sentences P £ IA~<C. 

Definition 2. For any A £ r(Lp L ), let: 

C A = max {C £ r(L£ L ) | P F (A/C) £ A} 

where max P = {A £ P | VP £ P : if\~pL A — > B then \~pl B -o- A}, P C Lpl- 
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Remark 2. Definition 2 identifies the most general circumstances C in which 
A is P F -permitted. As we shall see (L7), for any A there is just one such C 
(we write Ca) that also has the useful property of owning, for any Oa £ 0 , 4 , 
some basis Oc A £ ©cu such that b PP Oa H (iA @c A ) (cf- L9), which in 
turn means that just these general circumstances need to be considered in 
the construction of the canonical I. To the same effect, Spohn [24] identifies 
the most general circumstances by the use of equivalence classes [A]~ defined 
via ‘permission circles’: A sa B iff B is in some {Pi, ..., B n } C r(Lp L ) such 
that P F (Bi/A), P F (B 2 /Bi), P F (B n /B n _ 1 ), P F (A/B n ) are in A. As can be 

shown, the set of all such classes is {[A]~ | A = C p for some B £ r(Lp L )}. 

We prove some observations regarding Ca: 

(L3) If P f {A/D) £ A then there is a C £ Ca :l ~pl D — » C. 

Proof: Immediate from the definition of Ca and the finiteness of r(Lp L ). 
(L4) For all A £ r(L PL ): Ca y^ 0. 

Proof: P F (A/A) £ A follows from (L2) and (DD F ), (CExt), so Ca y^ 0 
follows from (L3). 

(L5) For all C £ Ca for some A £ r(L PL ), we have C c = {C}. 

Proof: If C £ C c then P F (A/C), P F (C/C), P F (C/C) £ A, using (FH) 
we obtain P F (A/C V C'),P F (C/C V C) £ A, so C = (C V C) = C . 

(L6) For all C £ Ca for some A £ r(L PL ), if P F {C/D ) £ A then b pl D ^ C. 

Proof: If P F (C/D) £ A then from P F (A/C) £ A and (FH) it follows 
that P F (A/ C V D), so C = (C V D), \- PL D — > C. 

(L7) For all A £ r(Lp L ), there is some Ca such that Ca = {Ca}- 

Proof: Ca y^ 0 (L4). Assume C,C' £ Ca- P f {A/A) £ A, so \~pl A — > C 
(L3). P F (A/C'), P F (A/C) £ A by definition, P F (C/C') £ A by use of 
(DM), (CExt), so we get P F (A/CVC') £ A from (FH), so C = (CVC') = C . 

(L8) For all A £ r(L£ L ): h PL 0% ++ (A A 0§J. 

Proof: We have b PP A^ Ca and O s (O s a /A) £ A, so with (Up) we obtain 
0 s (A — > O a /Ca) £ A. So b PL (A A 0 F 4 ) — > O A which is the right-to- 
left direction. For the left-to-right direction, b PP O S A —> A follows from 
(CExt), and from O s (O f a /Ca) ,P f (A/Ca) £ A we get O s (O f a / A) £ A 
with (RM). So b PL O s A ^ {A A O f a ). 

(L9) For all A £ r(L PL ), Oa £ O^: 30 Ca £ ©£ : b PL O a (A A 0 Ca ). 

Proof: Let Oa £ © F > so O f (Oa/A) £ A. b PP A — ► Ca, with (Up) 
we get O f (A — > Oa/Ca) £ A, and so there is some Oc A £ © F A with 
b PL (A A O 0a ) -d Oa- Assume P f {^0 Ca /A) £ A. From 0 f {0 Ca /C a ) £ 
A and (Downl) we get O f (Oc a A ->A/Ca) and O f (~>A/Ca) £ A, 
which contradicts that P f {A/Ca) £ A by the definition of Ca- So 
O f {Oc a /A) £ A, and 0 F (A AO Ca /A) £ A by (CExt). Since b PP 
(A A Oc A ) — > Oa we then have b PP Oa £ (AA Oc a ) from the min- 
imality of Oa- 
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Definition 3. Let C = {C £ r(Lp L ) | C £ Ca) for some A £ r(Lp L )}. 

Remark 3. If this were ‘ordinary’ dyadic deontic logic with agglomeration and 
so just one basis Oc for any C, we would be almost done: Like Spohn [24] 
orders his equivalence classes [C]” by a relation before , C could be ordered into 
(Ci,...,C n ) with Ci = t, Ci + 1 = Ci A and C n = k. S = (Si,...,S n ) with 

Si = ( Ci A -iCj+i), 1 < i < n, is then the ‘system of spheres’, and v h v' iff 
v £ Si, v' £ Sj, i < j defines the corresponding preference relation. - Here, no 
sphere C £ C is guaranteed to have a single basis. But as it turns out, C has the 
structure of a ‘multiple’ system of spheres that is similarly identified. 

The following observations hold for any C £ C, Oc £ © F , D £ r(Lp L ): 

(L10) If {C -> O c } U {D}Yk then O f (C -> O c /D) £ A 

Proof: Assume {C — > Oc} U {D} Y- k. If O f (~>C/D) £ A then the con- 
clusion holds trivially. Otherwise P F (C/D) £ A, so h PL D — > C by (L6). 
For r.a.a. suppose P F (^Oc/D) £ A. With 0 F (Oc/C) £ A we obtain 
O f (Oc A ->D/C) £ A by (Downl), and b PP Oc — > ~>D by minimality 
of Oc- But then Y PP D — > (C A -'Oc), which refutes the assumption. So 
instead 0 F (Oc/D) £ A and O f (C -A Oc/D) £ A by use of (CExt). 

(Lll) {t,k}C C 

Proof: P F (t/t) £ A by (DD F ), and h PL C — > t for any P F (t/C ) £ A, 
so t £ C t , t £ C. Concerning k, P F {k/k ) £ A by (DD F ), and due to 
(DN f ) C = k for any C such that P F (k/C) £ A, so k £ Cfe, k £ C. 

(L12) Cca^Oc ~ C A ~^Oc- 

Proof: The right-to-left direction is obvious from (DD F ), (CExt), and 
(L3). For the left-to-riglrt direction, suppose Y P l Ct/\^O c (C A ~>Oc), 
so {C -£ O c }U{C C A^o c } ^pl k. We obtain O f (C -> O c /C C a^o c ) € A by 
application of (L10), but P F {C A ^Oc/Cca^O c ) £ A by the construction 
of Cca^Oc so ^ is DDFS-inconsistent , but we assumed otherwise. 

(L13) If bp£ C — > D, then C = D or Y P l C — > (D A ~^Od) for some O p £ O^. 

Proof: Either P F {C/D) £ A, so h PL D C, C = D (L6). Or O f {-^C/D) 
£ A, so \~ PP O p — > —>C for some O p £ Op], and \~ PP C — > (D A —>O p ). 
(L14) D {D A —*O d ), and if D + k then D ± {D A -■£>£,). 

Proof: If D = (D A -^Op) then \- PL D — > ~>Op. But also \~ PL Op — > D 
due to (CExt), so Op = k and 0 F (k/D) £ A by (L2). But P F (t/D) £ 
A by (DD f ), so with (DDef) this contradicts DDFS-consistency of A. 
D ^ (D A £) Op), D ^ k, is proved likewise by use of (DD S ). 

(L15) Let C* be such that (i) t £ C*, and (ii) for any C* £ C*, Oc- £ © F , : 
(C* A O c -) £ C*. Then C = C*. 

Proof: C* C C is immediate from (Lll), (L12). As for C C C*, for each 
C £ C there is some C* £ C* such that (a) \~ PP C — > C* , and (b) for no 
Oc * £ © F » :bp£ C — > [C* A ^Oc-)- (a) is guaranteed by t £ C*, and (b) 
follows from (L13), (L14), and the finiteness of r(Lp L ). 
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Definition 4 (Canonical Construction). For any C £ C ,D £ r(Lp L ), let 
SUCC(C) = {C £ C I 30c £ : C' = (C A -O c )}, 

F-CHAIN(C) be the set of all (C±, ... ,C n ) such that C\ = t, C n = C, and for 
any i with 1 < i < n, C*+i £ SUCC(Ci), 

S-CHAIN(C, D) be the set of all (D\, ...,D n ) such that D\ = t, D n = D, 
(Di, ..., Dk) £ F-CHAIN(C), 1 < k < n, D n A D n _i, and for any i with 
k < i < n, D i+ i = Di A -'Of). 

For any C £ C, C £ SUCC(C), let 

7r : C —>■ [Prop — Lp L ] be a function that associates a unique proposition 
letter not occurring in 6 with each element ofC, 



<t>(C,C') = tt(C') A A {->7r(C ,/ ) | C" £ SUCC(C),C A C"}, 
a(C) = A{-tt (C') | C £ SUCC(C)}. 



For any C £ C, C A t, ch(C) = (Ci, £ F-CFtAIN(C) , let 

i F [ch{C)\ = - C A Air/ 



For any C £ C, ch{C,D) = {D u ...,D n ) £ S-CHAIN(C, D ) , =C, H 






A 



0"(C) A Ati 0(C»,C i+1 ) i/CAf, 

cr(C) otherwise. 



Finally, let 

I F = {i F [ch(C)} | C £ C, C A fc, c/i(C) £ F-CHAIN(C)}, 
I s = {i s [ch(C, D)\ | C £ C ,ch(C,D) £ S-CHAIN(C, D)}, 
I = I F UI S . 



Remark f. Definition 4 gives the construction tools and the construction of the 
canonical set I that makes all of A true. SUCC(C) is the set of immediate 
‘contrary-to-duty’ successors C of C , i.e. there is some basis Oc £ O f with 
C =C A ~<Oc. As (L15) showed, each C £ C is a successor of (a successor of ...) 
t, and F-CHAIN(C) is the set of all such nestings beginning with t and ending 
with C. The label <j> is used to make any two i F [ch(C')\, i F [ch(C")\, C and C" 
being successors of (successors of...) C , inconsistent with each other and with 
any i s [ch(C,D)\ via a. As C is finite, so is the number of proposition letters 
introduced by n, and hence are I F , I s and I. 

Lemma 1 (Properties of the Construction). For all C, C £ C, D £ r(Lp L ), 

a) if (Di , ..., D n ) £ F-CHAIN{C) or S-CHAIN(C,D) then b PL C i+1 -f C* and 
P pl Ci — > C i+1 , 1 < i < n, 

b) {i F [ch(C)}, i F [ch(C')]} \~pl k or ch(C ) is a segment of ch(C') or vice versa, 

c) {i s [ch(C, D)],i s [ch(C' , D')]} \~pl k or ch(C,D) = (Di, ..., Df) is a segment 
of ch(C' , D') = (Di , ..., D n ), Dk = C = C' , k < i < n, or vice versa, 

d) {i F [ch(C)\,i s [ch(C' , D)]} \~pl k or ch(C) = (Ci,...,C,) is a segment of 
(Di , ..., D n ), Dj. = C , 1 < i < k < n, 

e) no i F [ch(C)}, i s [ch{C,D)] £ I is a contradiction. 
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Proof, a) follows from the constructions of F-CHAIN and S-CHAIN and (L14). 
b)-c) follow from the definitions of f> and a. For d), note that each i £ I consists 
of a r(Lp L )-conjunct and a [Lpl — Lp L ]-conjunct. For i F [ch(C)\, the r(Lp L )- 
conjunct is ~>C which is consistent since C = t is excluded. For i s [ch(C, D)], 
the r(Lp L )-conjunct is ->£), so suppose D = t. Let ch(C,D) = (Di, D n ): 
due to the construction n/1, but then D\ = D n = t contradicts a). For the 
[Lpl — Lp L ]-conjuncts of i F [ch(C)\, let ch(C) = (Ci, ...,C n ) £ F-CHAIN(C ): 

— No conjunct 0(Ci,Cj+i), 1 < * < n, is a contradiction: For any C',C" £ C, 
7 r(C') ^ 7 r(C"), and no 7 r(C') occurs negated and unnegated in 0(C;,Cj + 1 ). 

— If 7 r(C') occurs unnegated in <j>(Ci,Ci+ 1 ) and negated in <j>(Cj,Cj+ 1 ), i < j, 

then C = C i+ 1 and C' £ SUCC(Cj). So there is a ch(C') £ F-CHAIN(C'), 
ch(C') = (Ci, ,Ci + 2 , ...,Cj,C'). which violates a). 

— If 7 r(C') occurs negated in (j>(Ci,Ci+ 1 ), and unnegated in <f>(Cj,Cj+i), i < j, 
then C £ SUCC(Ci) and C = Cj + 1 . From h pl Cj + i —1 C,+i we obtain 
l-pi C' — > Ci+i. So there are 0^,0^. £ © F . with C = Ci !\ -i0c 4 , C,;+i = 

and \~pl (Cj A->0c 4 ) — > (C* A -’0£.). Then h pl Of-. — > (Ci -A Oof), 
and with (CExt) \~pl Of. —1 0<y. ■ By minimality 0^. = 0c, and C = Ci+ i> 
but 4>(Ci,Ci- |_i) left 7 r(Cj+i) unnegated. 

For the [Lpl — Lp L ]-conjuncts of i s [ch(C, D)}, the case that 7 r(C') occurs un- 
negated in <j)(Ci,Ci + \) and negated in a(C) is done like the second case above. 

Lemma 2 (‘Coincidence Lemma’). For all A,B £ r(Lp L ): 

(a) I f= O f (A/B) iff O f (A/B) £ A 

(b) 1 1= P f (A/B) iff P f (A/B) £ A 

(c) 1 1= O s (A/B) iff O f (A/B) £ A 

(d) I\=P S (A/B ) iff P f (A/B) £ A 

Proof. I give the riglrt-to-left directions only, the others hold due to (DDef). 

Case a) Assume O f (A/B ) £ A, so some Op £ ©b derives A. By (L9) there 
is a Cb £ C, Oq b £ © F B such that h pl ((Cb Oc B ) Ail) £ Ob- By (L12) 
(Cb A ~^Oc b ) £ C, so for some chfCp A ->0c B ) £ F-CHAIN(Cb A ~^Oc B ) we have 
i F [ch(Cs A ~'Oc B )\ £ I- If {i F [ch(Cs A ~<Oc B )\, B} \- PL k this must be due to 
its r(Lp L )-conjunct Cb — > Oc B , since the others are consistent (Lemma 1 e) and 
not relevant for a derivation of ->B. But if {Cb — > Oc b ,B} \~pl k then Ob = k 
which contradicts P F (t/B) £ A by (DD F ) and the DDFS-consistency of A. So 
{i F [ch(Cs A ^Oc B )}, B} Ppl k, so for some P £ IA->B: I ' U {B} h pl A. 

Case b) Assume P F (A/B) £ A and for r.a.a. suppose that there is some 
I ’ £ J-L-i-B : V U {B} h PL ->A. If P fl I F 0, then there is a i F [ch(C)} £ P 
such that ch(C) is an initial segment of any ch(C ) or ch(C\D) with i F [ch(C')] 
or i s [ch(C',D)] £ I' (Lemma 1 b, cl). Concerning the r(Lp L )-conjuncts ~>C of 
i F [ch(C )] and ->D of any other i £ I', we have \~pl ~C —> ->D by Lemma 1 
a), so {~<C} U {B} h pp -i A since no [Lpl — Lp L ]-conjunct is relevant. C t 
by the construction, so ~>C = (C" -A Oc») for some C" £ C. (C" Oq"} U 
{B} Ppl k since else i F [ch(C)\ could not be in I', so 30 b £ Op :\~pl Ob — > 
(C" — > Oc ") due to (L10). Since I ~pl Ob — > B we obtain h pl Ob -* ~>A, 
O f (~<A/ B) £ A, so A is DDFS-inconsistent. Hence I F fl P = 0. If I s fl P 0 
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then there is a i s [ch(C, D)) G /' such that ch(C , D) is a segment of any ch(C ' , D') 
with z s [c/i(C', D')\ G /' (Lemma lc). Regarding the r(Lp L )-conjuncts ->D of 
i s [ch(C , D)] and -iD' of any other i G I', we have bpp -> D -> D' by Lemma la), 

so again {-i.D}U{B} bpp -iA since no [L pl — Lp L ]-conjunct is relevant. ch(C,D) 
is (Di , ..., D n ), n > 1, ->D = D„_i — > C?£ n _ i . If B„_i = C then either C = t, 
then bpp B — »• D n _i, or there is a i F [c/i(C)] G I F such that its r(Lp L )-conjunct 
-i C derives ->D (Lemma la), and its [Lpp — Lp L ]-conjunct is derived by that of 
i s [ch(C, D)]. So if i F [ch(C)\ (f I ’ then { — >C } U { } b pp k and bpp B — > D n _\. If 
D n - 1 yf C then there is a i s [ch(C,D n _ i)] ^ I' from which bpp B D n _ i 
is similarly obtained. So O s (B — > ->A/Z) n _i) G A. P F (A/B) G A derives 
P f (^(B — > -iA)/B) G A, so O s ((B — > ->A) A ->B/D n -\) G A due to (Down3). 
Hence bpp Of, ni — > ->B, bpp B — > D, so i s [ch(C, D)] ^ /', and I 1 C\ I s = 0. 
So 1 — 0 and {B} bpp -iA. With P F {A/B ) G A and (CExt) we get P F (k/B), 
so D = k due to (DN F ). But then 7_L-iB = 0 which completes the r.a.a. 

Case c) Assume O s (A/B) G A , and for r.a.a. suppose that there is some 
I' G I±-<B : I'U{B} b A. Suppose I F (1I' yf 0, so of some i F [ch{C)\ G /', c/i(C) is 
an initial segment of any ch(C') or ch(C' , D) with z F [c/i(C')] or i s [ch(C' , £))] G /' 
(Lemma 1 b, d). C = (C" A ^Ce") for some C" G C, Oc G 0 F „. We have 
hpi B -> C": This is trivial if C" = t, otherwise there is a i F [c/i(C ,/ )] G I F such 
that ch{C") is an initial segment of ch(C). The r(Lp L )-conjunct of i F [ch(C")] 
is -iC", which derives any r(Lp L )-conjunct of i*[ch{C)\ G /' (Lemma la). The 
[Lpl — Lp L ]-conjuncts of i F [ch(C")] derive from any such conjuncts of i F [ch(C')] 
or i s [ch(C',D)\ by the construction of <j>, tr, so if i F [ch(C ")] ^ /' then {-■ C"} U 
{B} b pl k, so bpp B — > C" . I' U { B } b pl C" — > Oc", so I' U {B} b pl Oc ■ By 

(DC FS ) and the minimality of Oc", b pp Oc —> 0 F n , so b Pi 0%, -A (B -> 0%) 
by (Up). So I' U {B} b pl Og and /' U {B} bpp A, refuting the assumption. So 
I F nl' = 0. Suppose I s HI' y^ 0, so there is a 't‘ s [c/i(C, U)] G V such that ch{C , D) 
is a segment of any ch{C',D') with i s [ch(C', D')\ G I' (Lemma lc). ch(C,D) = 
(Di, ...,D n ), n > 1, {z s [cft(C, D)]} bpz, and ~^D = D n _ i — ► Of) n i . Like in 
the previous case we prove that bpp B — > D n _ i, so /' U {!?} bpp . By 

use of (Up) b p L O s Dri i -> (B -> Of), but O s (A/B) G A, so /' U {B} b PL A, 
refuting the assumption. So /' ft I s = 0. For any B G r(L PL ), there is a Cp G 
C, and for any B ^ k a z' s '[c/i(Cb, (Cp A -iO^ B ))] G / s . If /' fl I s = 0 then 
{i s [c/i(CB, (Cp A ^C>Cb))]} u I - pl k, and {Cp — > 0^1 u i- 8 } * since 

only the r(Lp L )-conjunct is relevant. So bpp B — » O f b , Cp = A; by (L8), and 
D = k due to (DD S ). But then /_L->B = 0 which completes the r.a.a. 

Case d) Assume P S (A/B) G A. B y^ k due to (DN S ) and (CExt). Then 
i s [ch{Cs , (Cp A^C^ b ))] G I s is in some I' G I±->B for else B = k (see above). If 
i F [ch{C')\ G I' then ch{C) is a segment of c/i(Cp, (Cp A ^C^ B )) (Lemma Id), so 
_, C / — > ->Cp, and since bpp B — > Cp also bpp -nC' -»-.B. So i F [c/i(C')] 0/' 
and /' fl / F = 0. Suppose i s [c/i(C', B')] G /', then cft.(Cp,(Cp A is 

the initial segment of ch(C',D') (Lemma lc), so its r(Lp L )-conjunct ->D' is 
derived by that of i s [c/i(Cp, (Cp A ))]. No other conjuncts are relevant, so 
if J'UB bpp A then {Cp — > Cg s )}U{B} bpp A, but then by (L8) bpp 0% —t A, 
so O s {A/ B) G A and A is inconsistent. So I' LI B bpp A. 
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Corollary 1. Let P be a non-empty set of preference relations P C B x B 
such that each P is transitive, connected, and satisfies (LA h ): if ||A|| ^ 0 then 
bestp(A) 0, where bestp(A) = {i> £ ||A|| | Mv' £ ||A|| : vPv'}. 

Let L DDF +g be like Lddfs except that O f+ ,P f+ replace O f ,P f , and let the 
truth definitions for the deontic operators read: 

P \=O f+ (A/C) iff 3P £ P : bestp(C) C ||A|| 

P \=P F+ (A/C) iff VP £ P : best P {C) fl ||A|| ^ 0 

P t= O s (A/C) iff VP £ P : best P (C) C ||A|| 

P t= P S (A/C) iff 3P £ P : best P (C) n ||A|| ^ 0 

Let DDF + S be like DDFS except that (DN F ) and (DD F ) are replaced by 
(DN f +) 0 F+ {t/C) 

(DD f +) IfFp L -,C then h DDF+S P F+ (t/C) 

Then DDF + S is sound and (weakly) complete with respect to the above semantics. 

Proof (Sketch). To prove soundness , Arrow’s axiom: bestp(C V D) fl ||Cj| = 0 
or bestp(C) = bestp(C\/ D) fl ||C||, is helpful. For weak completeness , use trans- 
lations f~ and f + , where f~ : L DDF + S — > Lddfs just replaces any occurrence 
of O f+ (A/C) with (P F (fc/C) V 0 F (A/C )) and of P F +(A/C ) with ( 0 F {t/C ) A 
P F (A/C)), and f + : Lddfs —> L DDF + S replaces any occurrence of O f (A/C) 
with (P F (t/C) A 0 F+ (A/C)) and of P F (A/C) with \o F+ (k/C) V P F+ (A/C)) 
(cf. [2] § 28). Now prove that 

a) if I-ddfs ^ then P DDF + S f + (A) 

b ) if b DDF+S A then \~DDFS ,f~( A ) 

C ) b DDF+S A iff b DDF+S f + {f~{A)) 
d) Lddfs a iff Pddfs / (f + ( A )) 

To prove that if L DDF + S A then P DDF + S A, suppose L DDF + S A, so L DDF + S 
f + (f~(A)) by c), so Fddfs f ~( A ) by a). Repeat the construction for the canoni- 
cal set I as described in Def. 4. Let (Pi, ..., D n ) £ F-CF[AIN(k) or S-CF[AIN(C, k), 
C £ C, and let S(^D 1 ,...,D n ) = {Si, ...,S n -i) where Si = (Cj A -iC)+i), 1 < i < n. 
For any such (Pi, ... ,D n ), define P(Di,...,d„) C B x B by 
vP(D 1 ,...,D n )v' iff v £ ||5i||, v' £ \\Sj\\, and i < j, 
and let P be the set of all such relations. Due to (Lll), at least P(t,k) £ Pi so 
P / 0. By use (Lemma 1) it can be easily verified that each v £ B belongs 
to exactly one sphere Si in S^ 1 d ) = {Si, S n -i), 1 < i < n, and so 
P (D i„. , D n ) £ P is transitive and connected and satisfies (LA L ). Finally 
P LO F+ (A/B) iff f-(0 F+ (A/B)) £ A 
P LO s (A/B) iff O s (A/B) £ A 

is proved by appealing to the construction of the canonical set I and Lemma 2. 

Remark 5. The corollary exploits the notorious parallels to Spolm’s complete- 
ness proof for B. Hansson’s DSDL3. The two deontic operators are interpreted 
by Hansson-type truth definitions which validate the characteristic theorems 
0*(A/A) for both. This is the main difference to the multiplex preference mod- 
els devised by Goble [7]: there the truth of deontic operators also depends on 
some or all members of a non-empty set of preferences, but the truth definitions 
are Danielsson-type (cf. [2] p. 219). 
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5 Conclusion 

It has been shown that the truth definitions for the monadic deontic operators 
O f and O s which were devised by van Fraassen and Horty to deal with openly 
conflicting norms, can be adjusted to also cover predicaments that arise in sub- 
ideal situations; the thus defined dyadic operators then characterize the dyadic 
deontic logic DDFS. This result may also be found interesting from the perspec- 
tive of belief dynamics, since e.g. O f (A/C ) is true with respect to a set / iff A 
derives from a maxichoice contraction of I by —>C expanded by C, and (some- 
what) similar for O s {A/C) and full meet contraction. It is, insofar as I know, 
a new result: In particular the equivalences proven by Rott [23] between oper- 
ators of theory change, systems of nonmonotonic reasoning, and choice theory 
only cover nonmonotonic systems that include agglomeration. - I have briefly 
commented above on the problem of ‘consistent aggregation’ for van Fraassen’s 
monadic operator O f (also cf. the bimodal extension in my [8]), and must leave it 
to future examination if and how this problem can be solved in a dyadic context. 
Missing in the present account are also ‘proper’ conditional imperatives that are 
only included in a set of actualized imperatives (used to define some score) if 
their condition is ‘triggered’ (cf. van Fraassen’s intermediate definition in [28] ) 8 . 
To examine how the present contrary-to-duty conditionals combine with others 
expressing ‘proper’ conditional obligations must be left to future study. 
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Abstract. In this paper, we combine deontic logic with Alternating- 
time Temporal Logic (ATL) into a framework that makes it possible to 
model and reason about obligations and abilities of agents. The way both 
frameworks are combined is technically straightforward: we add deontic 
accessibility relations to ATL models (concurrent game structures), and 
deontic operators to the language of ATL (an additional operator UP 
is proposed for “unconditionally permitted” properties, similar to the 
“all I know” operator from epistemic logic). Our presentation is rather 
informal: we focus on examples of how obligations (interpreted as re- 
quirements) can be confronted with ways of satisfying them by actors of 
the game. Though some formal results are presented, the paper should 
not be regarded as a definite statement on how logics of obligation and 
strategic ability must be combined; instead, it is intended for stimulat- 
ing discussion about such kinds of reasoning, and the models that can 
underpin it. 

Keywords: deontic logic, alternating-time logic, multi-agent systems. 



1 Introduction 

In recent years, there has been increasing interest from within the computer sci- 
ence, logic, and game theory communities with respect to what might be called 
cooperation logics: logics that make it possible to explicitly represent and reason 
about the strategic abilities of coalitions of agents (human or computational) in 
game-like multi-agent scenarios. Perhaps the best-known example of such a logic 
is the Alternating-time Temporal Logic of Alur, Henzinger, and Kupferman [1], 
In this paper, we propose a concept of “deontic ATL”. As deontic logic focuses 
on obligatory behaviors of systems and agents, and Alternating-time Temporal 
Logic enables reasoning about abilities of agents and teams, we believe it inter- 
esting and potentially useful to combine these formal tools in order to confront 
system requirements (i.e., obligations) with possible ways of satisfying them 
by actors of the game (i.e., abilities). This paper is not intended as a definite 
statement on how logics of obligation and strategic ability should be combined. 
Rather, we intend it to stimulate discussion about such kinds of reasoning, and 
the models that can underlie it. 

We begin by presenting the main concepts from both frameworks. Then, in 
section 2, their combination is defined and discussed. Three different approaches 
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to modeling obligations in a temporal context are discussed: global requirements 
on states of the system (i.e. , that deem some states “correct” and some “incor- 
rect”), local requirements on states (“correctness” may depend on the current 
state), and temporal obligations, which refer to paths rather than states. We 
investigate (in an informal way) the perspectives offered by each of these ap- 
proaches, and present several interesting properties of agents and systems that 
can be expressed within their scope. Some preliminary formal results are given 
in Section 3. 



1.1 Deontic Logic: The Logic of Obligations 

Deontic logic is a modal logic of obligations [16], expressed with operator Op (“it 
is obligatory that ip” ) . Models for deontic logic were originally defined as Kripke 
structures with deontic accessibility relation(s) [21]. A state q' such that qlZq' is 
called a “perfect alternative” of state q (we can also say that q' is acceptable or 
correct from the perspective of q) . As with the conventional semantics of modal 
operators we define, 

M, q |= Op iff for all q' such that qlZq' we have M, q' \= tp. 

We believe that this stance still makes sense, especially when we treat deontic 
statements as referring to preservation (or violation) of some constraints one 
would like to impose on a system or some of its components (such as integrity 
constraints in a database) . In this sense, deontic modalities may refer to require- 
ments (specification requirements, design requirements, security requirements 
etc.), and we will interpret Op as “ p is required” throughout the rest of the 
paper. This approach allows to put all physically possible states of the system 
in the scope of the model, and to distinguish the states that are “correct” with 
respect to some criteria, thus enabling reasoning about possible faults and fault 
tolerance of the system [22] . However, we will argue that ATL plus deontic logic 
allows to express obligations about what coalitions should or should not achieve 
- without specifying how they do achieve it (or refrain from it) . We consider this 
issue in detail in Section 2.5. 

Let us illustrate our main ideas with the following example. There are two 
trains: a and b ; each can be inside a tunnel (propositions a-in and b-in, respec- 
tively) or outside of it. The specification requires that the trains should not be 
allowed to be in the tunnel at the same time, because they will crash (so the 
tunnel can be seen as a kind of critical section): iF(a-in A b-in) or, equivalently, 
CU( a-in A b-in). A model for the whole system is displayed in Figure 1A. 

Locality and Individuality of Obligations. Note that the set of perfect 
alternatives is the same for each state q in the example from Figure 1A. Thus, 
the semantic representation can in fact be much simpler: it is sufficient to mark 
the states that violate the requirements with a special “violation” atom V [2, 
15, 14]. Then the accessibility relation 1Z can be defined as: qlZq' iff q' V. 

Using a more elaborate accessibility relation machinery makes it possible, in 
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Fig. 1. (A) Critical section example: the trains and the tunnel. Dotted lines display the 
deontic accessibility relation. (B) The trains revisited: temporal and strategic structure 



general, to model requirements that are local with respect to the current state. 
Local obligations can provide a means for specifying requirements that evolve 
in time. Also, they can be used to specify exception handling in situations when 
full recovery of the system is impossible (cf. Section 2.3). 

Another dimension of classifying obligations is their individuality. The acces- 
sibility relation can define the requirements for the whole system, or there can be 
many relations, specifying different requirements for each process or agent [14]. 

Combining Deontic Perspective with Other Modalities. The combi- 
nation of deontic logic with temporal and dynamic logics has been investi- 
gated at length in the literature [15,20,7,18]. In addition, deontic epistemic 
logics [5,14] and BOID ( “beliefs-ob ligations- intentions-desires” ) logics [6] have 
also been studied. Finally, in [19], deontic and strategic perspectives were com- 
bined through applying social laws to ATL. 

1.2 Strategic Ability: Alternating-Time Temporal Logic 

Alternating-time Temporal Logic (ATL) [1] extends the computation tree logic 
(CTL) with a class of cooperation modalities of the form ((A)), where A is a set 
of agents. The intuitive interpretation of (( A))<P is: “The group of agents A have 
a collective strategy to enforce <P no matter what the other agents in the system 
do” . The recursive definition of ATL formulas is: 

ip := p | ->tp | (fix V (p 2 | ((A»A :<p | ((A)) Gp | (( A))ip 1 Up 2 

The “sometime” operator F can be defined as: ((A)) Ftp = ((A))TUip. 

Models and Semantics of ATL. Concurrent game structures are transition 
systems that are based on the collective actions of all agents involved. For- 
mally, a concurrent game structure is a tuple M = (£, Q, 77, n, Act , d, S), where: 
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£ = {ai, ...,ak} is a (finite) set of all agents , Q is a non-empty set of states, 77 
is a set of (atomic) propositions, and ir : Q — > 2 n is a valuation of propositions; 
Act is a set of actions (or choices), and d : Q x £ -A 2 Act is a function that 
returns the decisions available to player a at state q. Finally, a complete tuple of 
decisions (aq, ..., oik) C d q (a\) x . . . x d q (ak) from all the agents in state q implies 
a deterministic transition according to the transition function S(q, aq, ...,ak) . 

A strategy for agent a is a mapping f a : Q + — > Act, which assigns a choice 
f a (qoi • ••> In) £ d a (q n ) to every non-empty finite sequence of states qo,...,q n . 
Thus, the function specifies a’s decisions for every possible (finite) history of 
system transitions. A collective strategy for a set of agents A C £ is just a tuple 
of strategies (one for each agent in A)-. Fa = ( f a )aeA ■ Now, out(q,FA ) denotes 
the set of outcomes of Fa from q, i.e., the set of all (infinite) computations 
starting from q, in which group A has been using Fa- Let A[i\ denote the All 
position in computation A. The semantics of ATL formulas follows through the 
clauses: 

M,q 1= ((A)) Xip iff there exists a collective strategy Fa such that for all 
A £ out(q, Fa) we have M, A[l] \= ip\ 

M,q 1= ((A)) Gp iff there exists a collective strategy Fa such that for all 
A £ out(q, Fa) we have M , A[i] \= <p for every i > 0; 

M,q 1= ((A))pUip iff there exists a collective strategy Fa such that for all 
A £ out(q, Fa) there is * > 0 such that M, A[i] h ip and for 
all j such that 0 < j < i we have M, A[j] 1= <p. 

Let us consider the tunnel example from a temporal (and strategic) perspec- 
tive; a concurrent game structure for the trains and the tunnel is shown in Fig- 
ure IB. Using ATL, we have that ((A’))F(a-in A b-in), so the system is physically 
able to display undesirable behavior. On the other hand, ((a))G^(a-inAb-in), i.e., 
train a can protect the system from violating the requirements. In this paper, 
we propose to extend ATL with deontic operator O in order to investigate the 
interplay between agents’ abilities and requirements they should meet. 

The Full Logic of ATL*. ATL* generalizes ATL in the same way as CTL* 
generalizes CTL: we release the syntactic requirement that every occurrence of 
a temporal operator must be preceded by exactly one occurrence of a coopera- 
tion modality. ATL* consists of state formulas tp and path formulas ip, defined 
recursively below: 

p:=p\^p\p 1 \J p 2 \ ((A))ip 
ip := ip | ~<ip | ipi V ip2 | Xip | ipi Uip2 

Temporal operators F and G can be defined as: Fip = T Uip and Gip = ~^F~>ip. 
ATL* has strictly more expressive power than ATL, but it is also more compu- 
tationally costly. Therefore ATL is more important for practical purposes. For 
semantics and extensive discussion, we refer the reader to [1]. 

1 The definition we use here differs slightly from the original one [1], because we use 
symbolic labels for agents and their choices (and we do not assume finiteness of Q 
and Act). For an extensive discussion of various ATL semantics, refer to [9]. 
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1.3 STIT Logic: The Logic of Causal Agency 

It is also worth mentioning at this point a related body of work, initiated largely 
through the work of Belnap and Perloff, on “stit” logic - the logic of seeing to it 
that [4, 3] . Such logics contain an agentive modality, which attempts to capture 
the idea of an agent causing some state of affairs. This modality, typically written 
[i stit </>], is read as “agent i sees to it that <j>" . The semantics of stit modalities are 
typically given as [i stit <j>\ iff i makes a choice c, and 0 is a necessary consequence 
of choice c (i.e., <j> holds in all futures that could arise through i making choice 
c) . A distinction is sometimes made between the “generic” stit modality and the 
deliberate stit modality (“dstit”); the idea is that i deliberately sees to it that (f> 
if [i stit <fi\ and there is at least one future in which <t> does not hold (the intuition 
being that i is then making a deliberate choice for <j>, as <j> would not necessarily 
hold if i did not make choice c) . Such logics are a natural counterpart to deontic 
logics, as it clearly makes sense to reason about the obligations that an agent 
has in the context of the choices it makes and the consequences of these choices. 
Similarly, if we interpret choices as programs (cf. the strategies of ATL), then 
stit logics are also related to dynamic logic [12]; the main differences are that 
programs, which are first class entities in the object language of dynamic logic, 
are not present in the object language of stit logics (and of course, strategies are 
not present in the object language of ATL). Moreover, stit logics assert that an 
agent makes a particular choice, whereas we have no direct way of expressing 
this in ATL (or, for that matter, in dynamic logic). So, while stit logics embody 
somewhat similar concerns to ATL (and dynamic logic), the basic constructs are 
fundamentally different, providing (yet another) way of interpreting the dynamic 
choice structures that are common to these languages. 

2 Deontic ATL 

In this section, we extend ATL with deontic operators. We follow the definition 
with an informal discussion on how the resulting logic (and its models) can help 
to investigate the interplay between agents’ abilities and requirements that the 
system (or individual agents) should meet. 

2.1 Syntax and Semantics 

The combination of deontic logic and ATL proposed here is technically straight- 
forward: the new language consists of both deontic and strategic formulas, and 
models include the temporal transition function and deontic accessibility rela- 
tion as two independent layers. Thus, the recursive definition of DATL formulas 
is: 



ip := p | -up | ^ V (p 2 | 0 A ip | UPaP | (( A))Xp | (( A))G<p \ {{A))ip 1 Upi 

where A C A is a set of agents. Models for Deontic ATL can be called deontic 
game structures , and defined as tuples M = (A, Q , II, 7r, Act, d, S , R), where: 
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— £ is a (finite) set of all agents , and Q is a non-empty set of states, 

— 77 is a set of (atomic) propositions , and tt : Q — > 2 n is their valuation ; 

— Act is a set of actions, and d : Q x S — »• 2 Act is a function that returns the 
decisions available to player a at state q- 

— a complete tuple of decisions (u\, ... ,otk ) C d q (a i) x ... x d q {ak) from all the 
agents in state q implies a deterministic transition according to the transition 
function S(q, a \, ..., a*,); 

— finally, R : 2 s 2 < 3 X< 3 is a mapping that returns a deontic accessibility 
relation 7 Za for every group of agents A. 

The semantic rules for p, -> ip,ipVij), ((A))Xip, ((A))Gip, ((A))ipUijj are inherited 
from the semantics of ATL (cf. Section 1.2), and the truth of OaP is defined 
below. We also propose a new deontic operator: GPtp, meaning that “tp is un- 
conditionally permitted”, i.e., whenever (p holds, we are on the correct side of 
the picture (which closely resembles the “only knowing” /“all I know” operator 
from epistemic logic [13]). 

M, q |= OaP iff for every q' such that qlZAq' we have M, q 1 |= ip ; 

M,q\= UPaP> iff for every q' such that M, q' |= (p we have qIZAd 1 ■ 

This new operator - among other things - will help to characterize the exact 
set of “correct” states, especially in the case of local requirements, where the 
property of a state being “correct” depends on the current state of the system. 

In principle, it should be possible that the requirements on a group of agents 
(or processes) are independent from the requirements for the individual members 
of the group (or its subgroups). Thus, we will not assume any specific relationship 
between relations 7 Za and 7 Za', even if A ' C A. We propose only that a system 
can be identified with the complete group of its processes, and therefore the 
requirements on a system as a whole can be defined as: Op = O^p. In a similar 
way: UPp = UPsp. 

2.2 Dealing with Global Requirements 

Let us first consider the simplest case, i.e., when the distinction between “good” 
and “bad” states is global and does not depend on the current state. Deontic 
game structures can in this case be reduced to concurrent game structures with 
“violation” atom V that holds in the states that violate requirements. Then: 

M, q \= (Dtp iff for all q' such that q 1 ¥■ V we have M, q' |= <p. 

As we have both requirements and abilities in one framework, we can look at the 
former and then ask about the latter. Consider the trains and tunnel example 
from Figure IB, augmented with the requirements from Figure 1A (let us also 
assume that these requirements apply to all the agents and their groups, i.e., 
TZ a = 7 Za' for all A, A! C A; we will continue to assume so throughout the rest of 
the paper, unless explicitly stated). As already proposed, the trains are required 
not to be in the tunnel at the same moment, because it would result in a crash: 
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0(^(a-in A b-in )) . Thus, it is natural to ask whether some agent or team can 
prevent the trains from crashing: ((A))G-i(a-in A b-in)? Indeed, it turns out that 
both trains have this ability: ((a))G^(a-inAb-in)A((&))G^(a-inAb-in). On the other 
hand, if the goal of a train implies that it passes the tunnel, the train is unable to 
“safeguard” the system requirements any more: _, ((a)) _, (a-inAb-in) G(a-inA^b-in). 

In many cases, it may be interesting to consider questions like: does an agent 
have a strategy to always/eventually fulfill the requirements? Or, more generally: 
does the agent have a strategy to achieve his goal in the way that does not violate 
the requirements (or so that he can recover from the violation of requirements 
eventually)? We try to list several relevant properties of systems and agents 
below: 

1. the system is stable (with respect to model M and state q) if M,q |= 
((0))G- <V, i.e. , no agent (process) can make it crash; 

2. the system is semi-stable (with respect to model M and state q) if it will 
inevitably recover from any future situation: M,q |= (( 0))G((0))F~>V ; 

3. agents A form a (collective) guardian in model M at state q if they can 
protect the system from any violation of the requirements: M, q |= {{A))G~>V; 

4. A can repair the system in model M at state q if M,q \= ((A)) F-W; 

5. A is a (collective) repairman in model M at state q if A can always repair 
the system: M,q |= ((0))G((A))F~ <V; 

6. finally, another (perhaps the most interesting) property is agents’ ability to 
eventually achieve their goal ((f) without violating the requirements. We say 
that agents A can properly enforce ip in M, q if M, q \= ((A))(-iU) G(-W A ip). 

We will illustrate the properties with the following example. The world is 
in danger, and only the Prime Minister ( p ) can save it through giving a speech 
at the United Nations session and revealing the dangerous plot that threatens 
the world’s future. However, there is a killer ( k ) somewhere around who tries to 
murder him before he presents his speech. The Prime Minister can be hidden 
in a bunker (proposition pbunk), moving through the city (pcity), presenting 
the speech (pspeaks = saved), or. . . well. . . dead after being murdered (pdead). 
Fortunately, the Minister is assisted by James Bond ( b ) who can search the 
killer out and destroy him (we are very sorry - we would prefer Bond to arrest 
the killer rather than do away with him, but Bond hardly works this way. . . ). 
The deontic game structure for this problem is shown in Figure 2. The Prime 
Minister’s actions have self-explanatory labels {enter, exit, speak and nop for 
“no operation” or “do nothing”). James Bond can defend the Minister (action 
defend), look for the killer {search) or stay idle {nop)', the killer can either 
shoot at the Minister {shoot) or wait {nop). The Minister is completely safe in 
the bunker (he remains alive regardless of other agents’ choices). He is more 
vulnerable in the city (can be killed unless Bond is defending him at the very 
moment), and highly vulnerable while speaking at the UN (the killer can shoot 
him to death even if Bond is defending him). James Bond can search out and 
destroy the killer in a while (at any moment). It is required that the world is 
saveable {0((E))F saved) and this is the only requirement {MP((E))F saved). Note 
also that the world can be saved if, and only if, the Prime Minister is alive 
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Fig. 2. James Bond saves the world. The arrows show possible transitions of the system; 
some of the labels are omitted to improve readability. The states that violate the 
requirements are marked grey 



(((E)) F saved = ^pdead), and the two states that violate this requirement are 
marked accordingly ( V = pdead). 

The system is neither stable nor semi-stable (the Minister can go to the 
UN building and get killed, after which the system has no way of recovering). 
Likewise, no agent can repair the system in states q7,qs, and hence there is no re- 
pairman. The Prime Minister is a guardian as long as he is in the bunker, because 
he can stay in the bunker forever: pbunk — > ((p))G^ pdead. However, if he does so, 
he cannot save the world: -, ((p))(^pdead) G(^pdead A saved). On the other hand, 
he can cooperate with Bond to properly save the world as long as he is initially 
out of the UN building: (pbunk V pcity) — »• ((p, &))(^pdead) W(^pdead A saved) 
he can get to the bunker, defended by Bond, and then wait there until Bond 
finds the killer; then he can go out to present his speech. Incidentally, there is 
one more guardian in the system - namely, the killer: (^pdead) — > ((fc))G^pdead, 
and also (->pdead) — > ((p, fc))(^pdead)t/(^pdead A saved), so the Minister can 
alternatively pay the killer instead of employing Bond. 



2.3 Local Requirements with Deontic ATL 

A more sophisticated deontic-accessibility relation may be convenient for mod- 
eling dynamics of obligations, for instance when the actors of the game can 
negotiate the requirements (e.g., deadlines for a conference submission). Alter- 
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Fig. 3. “James Bond saves the world” revisited: local requirements. Dotted lines define 
the deontic accessibility relation. Solid lines show possible transitions of the system 



natively, “localized” requirements can give a way of specifying exception handling 
in situations when a full recovery is impossible. 

Consider the modified “James Bond” example from Figure 3. The Prime 
Minister is alive initially, and it is required that he should be protected from 
being shot: q 3 |= ^pdead and q 3 j= CGpdead. On the other hand, nobody except 
the killer can prevent the murder: q 3 (= ((fc))G^pdead A -i((p, 6))G-ipdead; more- 
over, when the president is dead, there is no way for him to become alive again 
(pdead — > ((0})Gpdead). Now, when the Minister is shot, a new requirement is 
implemented, namely it is required that either the Minister is resurrected or the 
killer is eliminated: q-j |= 0(^pdead V kdead). Fortunately, Bond can bring about 
the latter: qi |= ((6}}Fkdead. Note that q 3 is unacceptable when the Minister is 
alive (q 3 ), but it becomes the only option when he has already been shot (gy) 2 . 

Similar properties of agents and systems to the ones from the previous section 
can be specified: 

1. the system is stable in M, q if, given M, q \= Op A UPp, we have M,q \= 

«0»Gp; 

2. the system is semi-stable in M,q if, given that M, q \= Op AUPp, we have 
M, q \=((0})G( P ^((0})Fp)- 

3. A form a guardian in M, q if, given M, q |= Op A UPp , we have M, q |= 

m)Gp\ 

4. A can repair the system in M, q if, given that M, q \= Op A UPp, we have 
M, q \=((A)}Fp ; 

5. group A is a repairman in M, q if, given that M,q \= Op A UPp , we have 
M,q\=((0}}G({A))Fp- 

6a. A can properly enforce tp in M , q if, given that M, q |= OaP A UPaP, we have 
M, q \= (( A))pU(p A ip). Note that this requirement is individualized now; 
6b. A can properly ( incrementally ) enforce ip in M,q if, given that 
M, q \= OaP A UPaP, we have M,q\= p A ip, or M,q\= p and A have a col- 
lective strategy Fa such that for every A £ out(q, Fa) they can properly 
(incrementally) enforce p in M, A [1] . 

2 In a way, we are making the deontic accessibility relation “serial” in a very special 
sense, i.e., every state has at least one reachable perfect alternative now. 
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The definitions show that many interesting properties, combining deontic and 
strategic aspects of systems, can be defined using semantic notions. However, at 
present, we do not see how they can be specified entirely in the object language. 

2.4 Temporal Requirements 

Many requirements have a temporal flavor, and the full language of ATL* allows 
to express properties of temporal paths as well. Hence, it makes sense to look at 
DATL*, where one specifies deontic temporal properties in terms of correct com- 
putations (rather than single states). In its simplest version, we obtain DTATL 
by only allowing requirements over temporal (path) subformulas that can occur 
within formulas of ATL: 

tp := p | -~ip | A ip 2 | {(A)) ip I 0 A ip I UPaiP 

with the path subformulas ip defined recursively as 

0 := Xip | Gip | (p\U(f 2 (where p E DTATL). 

Properties that can be expressed in this framework are, for instance, that 
OF (( r))Gip (it is required that sometime in the future, coalition r gets the oppor- 
tunity to guarantee tp forever) and OF(((r))Fip A (( r))F~«p ) (it is a requirement 
that eventually coalition r can determine ip). The latter can be strengthened to 

OG({{r))F<p A ((r))F-.ip) 

saying that it is an obligation of the system that there must always be op- 
portunities for r to toggle (p as it wants. Note that the definition of DTATL 
straightforwardly allows to express stability properties like 

OTip -)• «r»T0 

saying that r can bring about the temporal requirement Tip. 

Semantically, rather than being a relation between states, relation 704 is now 
one between states and computations (sequences of states). Thus, for any com- 
putation A, 0704 A means that A is an ideal computation, given q. The semantics 
of temporal obligations and unconditional permissions can be defined as: 



M,q\=0 A Xp 
M, q\=0 A Gip 
M, q |= 0 A pUip 



iff for every A such that qlZ A A, we have M, A[l] |= <p; 
iff for each A such that 0704 A, we have M, A[i] | = <p for all i > 0; 
iff for every A such that qlZ A A, there is * > 0 such that 
M, A[i] (=0 and for all 0 < j < i we have M, A[j] (= ip. 



M, q |= UPaX<p iff for every A such that M, A[l] f= ip, we have qlZ A X, 

M,q \=UPaG<p iff for every A such that M, Apt] |= p for all * > 0, we have 
0704 A; 

M. q |= lXP A pUip iff for every A, such that M,\[i] |= ip for some i > 0 and 
M, A[j] |= ip for all 0 < j < i, we have qTZ A ^- 
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One of the most appealing temporal constraints is that of a deadline: some 
property tp should be achieved within a number (say n) of steps. This could be 
just expressed by OX n ip 3 : only these courses of action are acceptable, in which 
the deadline is met. Note that the DATL obligation 0(((r))X) n ip expresses a 
different property: these are T who must be able to meet the deadline. 

Fairness-like properties are also a very natural area to reason about deontic 
constraints. Suppose we have a resource p that can only be used by one agent at 
the time (and as long as a is using it, p a is true). The constraint that every agent 
should always be able to use the resource is expressed by /\ a&s OG((a))Gp a - or, 
if this is an obligation of a particular scheduler s, we could write O s rather than 
O. Finally, let [T]^ be the shorthand for -i ((r))->^ (coalition r cannot prevent 
ip from being the case). Then, formula OG(((r))Fip [T]G(^ — > ((r'))F^ip)) 
says that only these courses of action are acceptable in which, might coalition T 
ever have a way to enforce ip, then it must “pass the token” to F' and give the 
other agents the ability to reverse this again. 

Note also that DTATL formulas UPi) > express a kind of “the end justifies 
means” properties. For instance, UPF kdead means that every course of action, 
which yields the killer dead, is acceptable. 



2.5 Deontic ATL and Social Laws 

We mentioned the two main streams in deontic logic, having either states of 
affairs or actions as their object of constraints. In Deontic ATL, one can express 
deontic requirements about who is responsible to achieve something, without 
specifying how it should be achieved. The requirement CG(({a, 6})).Fsafe-open, 
for example, states that it should be impossible for a and b to bring about the 
disclosure of a safe in a bank. However, with c being a third employee, we might 
have 0(-i(({a, 6}))Tsafe-open A (({a, 6, c}))Gsafe-open): as a team of three, they 
must be able to do so! We can also express delegation, as in O a ((b))Gip : authority 
a has the obligation that b can always bring about p. 

A recent paper [19] also addresses the issue of prescribed behavior in the 
context of ATL: behavioral constraints (specific model updates) are defined for 
ATL models, so that some objective can be satisfied in the updated model. The 
emphasis in [19] is on how the effectiveness, feasibility and synthesis problems 
in the area of social laws [18] can be posed as ATL model checking problems. 
One of the main questions addressed is: given a concurrent game structure M 
and a social law with objective p (which we can loosely translate as Op), can we 
modify the original structure M into M ' , such that M ' satisfies ((0))G<^? In other 
words, we ask whether the overall system can be altered in such a way that it 
cannot but satisfy the requirements. [19] does not address the question whether 
certain coalitions are able to “act according to the law”; the law is imposed on 
the system as a whole. Thus, the approach of that paper is prescriptive, while 
our approach in this paper is rather descriptive. Moreover, [19] lacks explicit 
deontic notions in the object level. 

3 OX n ip is not a DTATL formula, but the logic can be easily extended to include it. 
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An example of a requirement that cannot be imposed on the system as a 
whole (taken from [19]) is p A {{A))X-<p: property p is obligatory, but at the same 
time, A should be able to achieve ->p. This kind of constraints could be used to 
model “a-typical” situations, (such as: “it is obligatory that the emergency exit 
is not used, although at the same time people in the building should always 
be able to use it”). Putting such an overall constraint upon a system S means 
that S should both guarantee p and the possibility of deviating from it, which 
is impossible. It seems that our Deontic ATL covers a more local notion of 
obligation, in which 0{p A ((A))X~ip) can well be covered in a non-trivial way. 

On the other hand, our “stability” requirements are rather weak: to demand 
that every obligation Oip is implementable by a coalition does not yet guarantee 
that the system does behave well. Rather, we might be looking for something 
in between the universal guarantee and a coalitional efficiency with respect to 
constraint tp. And it is one of the features of Deontic ATL - that one can express 
many various stability requirements, making explicit who is responsible for what. 



3 Axioms, Model Checking and Similar Stories 

Let ATL and DL be the languages for ATL and deontic logic, respectively, and 
let AT C and VC be their respective semantic structures. Then - if we do not 
have any mixing axioms relating the coalitional and the deontic operators - we 
obtain a logic DATL = ATL ® DL which can be called an independent combi- 
nation of the modal logics in question [8] . [8] gives also an algorithm for model 
checking such a logic, given two model checkers for each separate logics. The 
communication overhead for combining the two model checkers would be in the 
order of m + J] Aep(a) nl 'J + n ■ l, where m is the number of coalitional transi- 
tions in the model, uia is the cardinality of the deontic access of coalition A , n 
is the number of states and l the complexity of the formula, leaving the model 
checking complexity of ATL ® DATL linear in the size of the model and the for- 
mula [8]. However, two technical remarks are in order here. First, the formal 
results from [8] refer to combining temporal logics, while neither ATL nor DL 
is a temporal logic in the strictest sense. Moreover, the algorithm they propose 
for model checking of an independent combination of logics assumes that the 
models are finite (while there is no such assumption in our case). Nevertheless, 
polynomial model checking of DATL is of course possible, and we show how it 
can be done in Section 3.2, through a reduction of the problem to ATL model 
checking. 

3.1 Imposing Requirements through Axioms 

Following a main stream in deontic logic, we can take every deontic modality to 
be KD - the only deontic property (apart from the K-axiom and necessitation 
for Op) being the D-axiom —>OpC. An axiomatization of ATL has been recently 
shown in [11]. If we do not need any mixing axioms, then the axiomatization of 
DATL can simply consist of the axioms for ATL, plus those of DL. 
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Concerning the global requirements, note that endowing AT C with a viola- 
tion atom V is semantically very easy. Evaluating whether Op is true at state 
q suggests incorporating a universal modality (cf. [10]) although some remarks 
are in place here. First of all, it seems more appropriate to use this definition of 
global requirements in generated models only, i.e., those models that are gener- 
ated from some initial state qo, by the transitions that the grand coalition S can 
make. Otherwise, the obligations might be unnecesarily weakened by consider- 
ing violations or their absence in unreachable states. As an example, suppose we 
have a system that has two modes: starting from q-\ , the constraint is that it is a 
violation to drive on the left hand side of the road l, and when the system orig- 
inates from 52 , one should adhere to driving on the right hand side (r). Seen as 
a global requirement, we would have 0(£ V r), which is of course too weak; what 
we want is Ol (for the system rooted in qi), or Or (when starting in 52 )- Thus, 
a sound definition of obligations in a system with root on is, that M, q 1= Op iff 
M,q 0 \={{<D))G(-,V^p). 

Second, we note in passing that by using the global requirement definition 
of obligation, the O modality obtained in this way is a KD45 modality, which 
means that we inherit the properties Op —> OOp and ->Op — > O^Op, as was 
also observed in [14]. But also, we get mixing axioms in this case: every deontic 
subformula can be brought to the outmost level, as illustrated by the valid scheme 
(( T))FOp -O- Op (recall that we have M, q \= (Dtp iff M, q 0 |= Op iff M, q ’ |= Op, 
for all states q, q' and root qo). Some of the properties we have mentioned earlier 
in this paper can constitute interesting mixing axioms as well. For instance, a 
minimal property for requirements might be 

O r p {{T))Fp 

saying that every coalition can achieve its obligations. Semantically, we can pin- 
point such a property as follows. Let us assume that this is an axiom scheme, 
and the model is distinguishing (i.e., every state in the model can be charac- 
terized by some DATL formula). Then the scheme corresponds to the semantic 
constraint: 



VqdFrVA € out(q,Fr) : states(X) fl img{q,lZr) yf 0 

where states(X) is the set of all states from A, and img(q, R) = {q' \ qRq'} is the 
image of q with respect to relation R. In other words, T can enforce that every 
possible computation goes through at least one perfect alternative of q. 

3.2 Model Checking Requirements and Abilities 

In this section, we present a satisfiability preserving interpretation of DATL into 
ATL. The interpretation is very close to the one from [9], which in turn was 
inspired by [17]. The main idea is to leave the original temporal structure intact, 
while extending it with additional transitions to “simulate” deontic accessibility 
links. The simulation is achieved through new “deontic” agents: they can be 
passive and let the “real” agents decide upon the next transition (action pass), 
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or enforce a “deontic” transition. More precisely, the “positive deontic agents” 
can point out a state that was deontically accessible in the original model (or, 
rather, a special “deontic” copy of the original state), while the “negative deontic 
agents” can enforce a transition to a state that was not accessible. The first ones 
are necessary to translate formulas of shape Oa'P'- the latter are used for the 
“unconditionally permitted” operator UP a- 

As an example, let M be the deontic game structure from Figure 3, and 
let us consider formulas Ch;saved, UPz saved and ((k, 6))Apdead (note that all 
three formulas are true in M, q 3 ). We construct a new concurrent game structure 
M atl by adding two deontic agents: rz, fz, plus “deontic” copies of the existing 
states: q^,q 7", <7s" an d ( l'l ■ ^7 ■ ( c ^- Figure 4). Agent rz is devised to point out 

all the perfect alternatives of the actual state. As state q 3 has only one perfect 
alternative (i.e., (73 itself), rz can enforce the next state to be q g Z , provided that 
all other relevant agents remain passive 4 . In consequence, (Dvsaved translates as: 
-'((rx',rx , ))A'( r 5i Asaved). In other words, it is not possible that rz points out an 
alternative of q 3 (while fz obediently passes), in which saved does not hold. 

Agent rz can point out all the imperfect alternatives of the current state (for 
qs, these are represented by: qf . qff ) . Now, UPzsaved translates as -<{{rz,fz))X 
(Fa A saved): fz cannot point out an unacceptable state in which saved holds, 
hence the property of saved guarantees acceptability. Finally, ((fc, 6))Apdead 
translates as ((k, b, rz , fz)) X (act A pdead): the strategic structure of the model 
has remained intact, but we must make sure that both deontic agents are passive, 
so that a non-deontic transition (an “action” transition) is executed. 

We present the whole translation below in a more formal way. An interested 
reader can refer to [9] for a detailed presentation of the method, and proofs of 
correctness. 

Given a deontic game structure M = (E, Q , 77, 7 r, Act, d, S, M) for a set of 
agents E = {ai, ..., a*,}, we construct a concurrent game structure 
M atl = (S', Q' , 77', 7r', Act', d' , S') in the following manner: 

- E’ = E\J E r U E r , where E r = {ta \ A C E, A y 0} is the set of “positive”, 
and E r = {r^ | A C E, A y 0} is the set of “negative” deontic agents; 

- Q' = Q U Uacz A^0(Q rA U Q rA )- We assume that Q and all <5 rA ,Q rA are 
pairwise disjoint. Further we will be using the more general notation S e = 
{q e | q € S'} for any S C Q and proposition e; 

- n' = n U {act, ..., r A , ...,Fa, ...}, and 7r'(p) = 7 r(p) U (J A cz( 7r (p) rA u? t (p) ? a ) 

for every p G 17. Moreover, 7r'(act) = Q, = Q rA , and 7r'(rA) = Q rA \ 

- d' q (a) = d q (a) for o G E,q € Q: choices of the “real” agents in the original 
states do not change, 

- d' q (r a) = {pass}Uimg(q,H A y A , and d' q (f A ) = {pass} U (Q \ img(q,H A )y A ■ 
Action pass represents a deontic agent’s choice to remain passive and let 
other agents choose the next state. Note that other actions of deontic agents 
are simply labeled with the names of deontic states they point to; 

4 We can check the last requirement by testing whether the transition leads to a 
deontic state of rs (proposition ) . It can happen only if all other relevant deontic 
agents choose action pass. 
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- Act' = Act U \J qe Q tA cs( d ' q ( r A) U d' q {r A ))\ 

— the new transition function for q £ Q is defined as follows (we put the choices 
from deontic agents in any predefined order): 

{ S(q, a ai , ...,a aic ) if all a r = pass 

if r is the first active (positive 
or negative) deontic agent 

— the choices and transitions for the new states are exactly the same: d'(q r *,a) = 
d'(q rA ,a) = d'(q,a ), and 6'(q' A , a ai , a rr , ...) = <5'(</ A , a ai , ..., a rr , ...) = 
d'(q, a ai , ..., a ak , ...,a rr , ...) for every q £ Q,a£ £',a a £ d'(q,a). 



Now, we define a translation of formulas from DATL to ATL corresponding to 
the above described interpretation of DATL models into ATL models: 



tr{p) 
tr{-np) 
trip V ip) 
tr(((A))Xip) 
tr{{{A))Gip) 
tr{((A))ipUip) 



tr(0 A <p) 

tr(UP A p) 



p , for p £ II 
-i tr{(p) 
trip) V tr(V’) 

{{A U U £ f ))X( act A trip)) 

tr(p) A ((A U £ r U £ f ))X{{A U £ r U i7))G'(act A trip)) 
trty) V itrip) A ({A U A r U £^))X({A U U £ f )) 

(act A trip)) Hi act A tri%p))) 

-^((£ r U r f ))A(r A A -.trip)) 

~ l {{£ r U £ r ))Xi? A Atrip)). 



Proposition 1. For every DATL formula p, model M, and a state q £ Q, we 
have M, q\= p iff M ATL ,q \= trip). 

Proposition 2. For every DATL formida p, model M, and “ action ” state q £ Q, 
we have M ATL , q |= trip) iff M ATL ,q e |= trip) for every e £ FF \ Ft. 

Corollary 1. For every DATL formida p and model M, p is satisfiable (resp. 
valid) in M iff trip) is satisfiable (resp. valid) in M ATL . 

Note that the vocabulary (set of propositions 77) only increases linearly (and 
certainly remains finite). Moreover, for a specific DATL formula p, we do not have 
to include all the deontic agents r A and f A in the model - only those for which 
O a or UP A occurs in p. Also, we need deontic states only for these coalitions 
A. The number of such coalitions is never greater than the complexity of p. 
Let to be the cardinality of the “densest” modal accessibility relation - either 
deontic or temporal - in A7, and l the complexity of p. Then, the “optimized” 
transformation gives us a model with ni! = Ofm) transitions, while the new 
formula trip) is on ly linearly more complex than p 5 . In consequence, we can 
use the ATL model checking algorithm from [1] for an efficient model checking 
of DATL formulas - the complexity of such process is O(toT') = 0(?nl 2 ). 

5 The length of formulas may suffer an exponential blow-up; however, the number of 
different subformulas in the formula only increases linearly. This issue is discussed 
in more detail in [9], 
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Let us consider again the deontic game structure from Figure 3. We construct 
a corresponding concurrent game structure, optimized for model checking of the 
DATL formula Qr^pdead A ((fc))X->Qj;^pdead): it is required that the Prime 
Minister is alive, but the killer is granted the ability to change this requirement. 
The result is shown in Figure 4. The translation of this formula is: 

~'({rz:))X( r E A ->(->pdead A ((k,r s ))X( act A -<-<{{rs))X( rr A ->-pdead)))) 
which holds in states q 3 and q r % of the concurrent game structure. 

4 Conclusions 

In this paper, we have brought obligations and abilities of agents together, en- 
abling one to reason about what coalitions should achieve, but also to formulate 
principles regarding who can maintain or reinstall which ideal states or courses 
of action. We think the tractable model checking of DATL properties makes the 
approach attractive as a verification language for normative multi-agent systems. 

However, as stated repeatedly in the paper, it is at the same time a report 
of ideas rather than of a crystallized and final analysis. We have not looked at 
an axiomatization of any system with non-trivial mixing axioms, nor have we 
yet explored some obvious routes that relate our approach in a technical sense 
with the work on social laws or the formal approaches that enrich ATL with an 
epistemic flavor, for instance. Nevertheless, we believe we have put to the force 
the fact that indeed DATL is a very attractive framework to incorporate abilities 
of agents and teams with deontic notions. We hope that the growing community, 
interested in norms in the computational context, can provide some feedback to 
help making appropriate decisions in the many design choices that we left open. 





On Obligations and Abilities 



181 



References 

1. R. Alur, T. A. Henzinger, and O. Kupferman. Alternating-time temporal logic. 
Journal of the ACM, 49:672-713, 2002. Updated, improved, and extended text. 
Available at http://www.cis.upenn.edu/~alur/Jacm02.pdf. 

2. A.R. Anderson. A reduction of deontic logic to alethic modal logic. Mind, 67:100- 
103, 1958. 

3. N. Belnap. Backwards and forwards in the modal logic of agency. Philosophy and 
Phenomenological Research, LI(4):777-807, 1991. 

4. N. Belnap and M. Perloff. Seeing to it that: a canonical form for agentives. Theoria, 
54:175-199, 1988. 

5. P. Bieber and F. Cuppens. Expression of confidentiality policies with deontic logics. 
In J.-J.Ch. Meyer and R.J. Wieringa, editors, Deontic Logic in Computer Science: 
Normative System Specification, pages 103-123. John Wiley & Sons, 1993. 

6. J. Broersen, M. Dastani, Z. Huang, and L. van der Torre. The BOID architecture: 
conflicts between beliefs, obligations, intentions and desires. In Proceedings of the 
Fifth International Conference on Autonomous Agents, pages 9-16, 2001. 

7. J. Fiadeiro and T. Maibaum. Temporal reasoning over deontic specifications. Jour- 
nal of Logic and Computation, l(3):357-396, 1991. 

8. M. Franceschet, A. Montanari, and M. de R.ijke. Model checking for combined 
logics. In Proceedings of ICTL, 2000. 

9. V. Goranko and W. Jamroga. Comparing semantics of logics for multi-agent sys- 
tems. Synthese, section on Knowledge, Rationality and Action, 2004. To appear. 

10. V. Goranko and S. Passy. Using the universal modality: Gains and questions. 
Journal of Logic and Computation, 2(l):5-30, 1992. 

11. V. Goranko and G. van Drimmelen. Complete axiomatization and decidability of 
the alternating-time temporal logic. Submitted, 2003. 

12. D. Harel, D. Kozen, and J. Tiuryn. Dynamic Logic. MIT Press, 2000. 

13. H.J. Levesque. All I know: a study in auto-epistemic logic. Artificial Intelligence, 
42(3):263-309, 1990. 

14. A. Lomuscio and M. Sergot. Deontic interpreted systems. Studia Logica, 75(1):63- 
92, 2003. 

15. J.-J.Ch. Meyer. A different approach to deontic logic: Deontic logic viewed as a 
variant of dynamic logic. Notre Dame Journal of Formal Logic, 29(1):109-136, 
1988. 

16. J.-J.Ch. Meyer and R.J. Wieringa. Deontic logic: A concise overview. In J.-J.Ch. 
Meyer and R.J. Wieringa, editors, Deontic Logic in Computer Science: Normative 
System Specification, pages 3-16. John Wiley & Sons, 1993. 

17. K. Schild. On the relationship between BDI logics and standard logics of concur- 
rency. Autonomous Agents and Multi Agent Systems, pages 259-283, 2000. 

18. Y. Shoham and M. Tennenholz. On the synthesis of useful social laws for artificial 
agent societies. In Proceedings of AAAI-92, 1992. 

19. W. van der Hoek, M. Roberts, and M. Wooldridge. Social laws in alternating time: 
Effectiveness, feasibility and synthesis. Submitted, 2004. 

20. J. van Eck. A system of temporally relative modal and deontic predicate logic and 
its philosophical applications. Logique et Analyse, 100:249-381, 1982. 

21. G.H. von Wright. Deontic logic. Mind, 60:1 15, 1951. 

22. R.J. Wieringa and J.-J.Ch. Meyer. Applications of deontic logic in computer sci- 
ence: A concise overview. In J.-.I.Cli. Meyer and R.J. Wieringa, editors, Deontic 
Logic in Computer Science: Normative System Specification, pages 17-40. 1993. 




On Normative-Informational Positions 



Andrew J.I. Jones 

Department of Computer Science, King’s College London, The Strand, 
London WC2R 2LS, UK 
a j i j ones@dcs . kcl .ac.uk 



Abstract. This paper is a preliminary investigation into the application of the 
formal-logical theory of normative positions to the characterisation of norma- 
tive-informational positions, pertaining to rules that are meant to regulate the 
supply of information. 



1 Introduction 

The theory of normative positions has provided a means of generating an exhaustive 
characterisation of the different types of normative status ( permitted , obligatory, for- 
bidden, and so on) that may be assigned to a given state of affairs. In the tradition of 
Kanger ([6], [5]), Lindahl [7], Jones & Sergot [4], the focus has usually been on the 
normative status of states of affairs of type ‘agent j brings it about that A’; for in- 
stance, the class of normative one-agent act positions generated by the method de- 
scribed in [4] consists of the following seven positions: 

(El) OEjA 

(E2) OEj-A 

(E3) 0(— iE^4 a — iEy— A) 

(E4) PEyl a PE r A a P(-E fj A a -.EpA) 

(E5) PE^A a PE j-A a 0(E f A v Ej-A) 

(E6) PEyl a — ,PEpA a P(— iEjA a —Ej—A) 

(El) — iPEyl a PE ; — A a PHE^A a -,EpA) 

There, Standard Deontic Logic (SDL) - a modal system of type KD in the Chellas 
classification [1] - is adopted for the logic of the obligation operator ‘O’, and the 
permission operator ‘P’ is the dual of ‘O’; and a modal system of type ET 1 is used for 
the relativised action modality ‘E/ . 

Given these choices for the deontic and action modalities, the method yields the re- 
sult that there are precisely these seven mutually exclusive normative positions for 
one agent vis-a-vis the state of affairs described by ‘A’. So either (El), the agent is 



1 This means, essentially, that the action modality is closed under logical equivalence, and 
satisfies the T. schema, the ‘success condition': EjA — > A. 

A. Lomuscio and D. Nute (Eds.): DEON 2004, LNAI 3065. pp. 182-190, 2004. 
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obliged to see to it that A, or (E2) he is obliged to see to it that -i A, or (E3) he is 
obliged to remain passive with respect to A, or. . ..and so on. 

The present report starts from the assumption that it might also be of interest to in- 
vestigate the normative status of another sort of state of affairs - of a type quite differ- 
ent from those represented by act descriptions - pertaining to the informational state 
of a given agent. By this is meant the state of affairs that an agent j is (or is not) in- 
formed that A, or is (or is not) informed that -i A. Consider, for instance, the situation 
of an individual j in relation to some government agency k that has responsibility for 
controlling the flow of information concerning A. What is the class of possible norma- 
tive positions for k (concerning the information j is permitted, forbidden, required, 
etc. to have about A) ? Or consider the situation of individual k in relation to some 
authority j (say, a court of Law), where k has certain obligations to supply information 
to j , or is permitted to withold information from k. In both of these contexts, among 
others, it would be useful to have at our disposal an exhaustive characterisation of the 
class of possible normative-informational positions, as they will here be called. 

Furthermore, since the original aim of the theory of normative positions, as pro- 
posed by Kanger and others, was to provide a formal-logical framework for the ar- 
ticulation of Hohfeldian rights-relations, it seems natural to suppose that the devel- 
opment of an account of normative-informational positions, along the lines indicated 
above, might also provide a platform for the systematic investigation of such rights as 
the right to silence, the right to know and the right to conceal information. However, 
the potential application domain for a theory of this kind would seem not to be con- 
fined to legal analysis, but might also contribute to the formal specification of the 
normative status of electronic information agents, whose tasks may include the acqui- 
sition of information, and the monitoring of information flow, among others. 



2 A Modality for ‘Informational State’ 

In [2, 3] modal-logical characterisations are given of the (forms of) conventions that 
constitute various key types of signalling acts: asserting, commanding, requesting, 
promising,.... among others. These characterisations employ several modalities, 
among them an ideality /optimality modality, ‘I* ’ 2 , used to represent those states of 
affairs that would obtain if a conventional signalling system were in an optimal state, 
relative to its function of facilitating the transmission of reliable information. For 
instance, if - according to the conventions constituting signalling system s - the hoist- 
ing on board a ship of a particular sequence of coloured flags counts as an assertion 
that the ship is carrying explosives, then - when on a particular occasion those flags 
are hoisted - the signalling system s would be in an optimal/ideal state, relative to its 
function of l’aciltating the transmission of reliable information, only if it were then 
indeed the case that the ship was carrying explosives. An observer, or audience, j, 
who is familiar with the conventions governing s and who witnesses the hoisting of 
this sequence of flags, will understand the meaning of the signal in the sense that he is 
aware of what would now be the case, given that the signaller is telling the truth. So 



2 The in the notation had no particular significance. It was introduced in the multi-modal 
language described in [2] merely to distinguish this particular notion of ideality from an 
evaluative normative modality, ‘I’, that also figured in the same language. 
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j’s informational state, following his observation of the flag-raising, is represented - 
on this approach - by a belief whose content takes the form ‘I* A’, where ‘A’ de- 
scribes the state of affairs that the ship is carrying explosives, j’s understanding the 
meaning of the signal amounts to his being aware that, were the signalling system v in 
an optimal state relative to its function of facilitating the transmission of reliable in- 
formation, ‘A’ would now be true. (Of course, if j also believes that the signaller is 
reliable, j will move on from the belief whose content is ‘P/L to the belief that A.) 

The modality ‘I* ’ was assigned the logic of the smallest normal modal system K. 
Closure under logical consequence would seem to be a natural assumption for this 
operator, given the intended interpretation. (For if signalling system s would be in an 
optimal state only if ‘A’ were true, then it could be in an optimal state only if the 
logical consequences of ‘A’ were also true.) Obviously, the T. schema 

(T.P) PjA — ¥ A 

does not accord with the indended interpretation. What of the D. schema 
(D.P) T*/ -A —i P,— A 

which is of course equivalent to 

-,( P S A a P s — A) ? 

Well, the validity of (D.P) would not be acceptable, for the simple reason that it 
would rule out the possibility of making inconsistent assertions. (It would be per- 
fectly possible, for instance, in many circumstances, for one or more signallers to 
raise the flag sequence that means (according to s ) that the ship is carrying explo- 
sives, and to raise the flag sequence that means (according to s) that the ship is not 
carrying explosives.) 

For the purposes of the present investigation into normative-informational posi- 
tions, an operator similar in interpretation to ‘I* ’ will be adopted, and will be denoted 
by T.\ where j is any agent. Expressions of the form ‘IyL will be understood to mean 
‘were the information supplied to j to be true, then ‘A’ would be the case’, or ‘accord- 
ing to the information supplied to j, ‘A’ is the case’. The simpler, and perhaps less 
accurate, readings ‘j is told that A’ and ‘j is informed that A’ may also be used, for 
ease of expression. For reasons parallel to those mentioned for the T*^’ operator, ‘I-’ 
will also be assigned the logic of a (relativised) normal modal operator of type K. 

In what follows, relativised versions of the obligation and permission modalities of 
Standard Deontic Logic (SDL), which is a normal modal system of type KD, will be 
employed to represent the normative component of the positions to be investigated. 
Expressions of the forms ‘O a A’ and ' P /( A ’ will be read ‘it is obligatory for k that A’ 
and ‘it is permitted for k that A’, respectively. Thus the agent k is understood to be the 
bearer of the obligation/permission. 

The problems associated with SDL are well documented in the literature. However, 
its adoption for the purposes of the present enquiry is defensible on the following 
three grounds: 

(a) the property of the closure of the operators under logical consequence will here 
be exploited in ways that appear to be innocuous; 
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(b) conditional obligation sentences will not figure in this investigation; it is surely 
in connection with the treatment of conditionals that SDL’s inadequacies are 
most fully exposed; 

(c) adoption of the D schema should simply be understood as a restriction on the 
enquiry to those normative systems that are well-formed, or well-organised, in 
the sense that they do not allow conflict of obligation of the form ‘O a A a O a 
—A’. In other words, the adoption of the D schema should not be understood as 
a claim to the effect that such conflicts cannot ever arise in any system of 
norms - but rather as a deliberate choice to focus on normative systems that are 
rationally organised, in the sense just described. It should be noted, however, 
that nothing in what follows presupposes that (where k and j are distinct agents) 
conflicts of the form ‘O k A a Oj-A’ could not arise. This is important in the 
present context since, for instance, one agent might well be required to reveal 
information, whilst another is required not to do so. 

Note, finally, as regards these comments on the selection of SDL, that the method 
of generation of normative positions employed below is itself independent of the 
particular choice of deontic logic (a point also emphasised in [4]). So anyone who 
remains unconvinced by the defence (a)-(c), above, can take from the shelf his fa- 
voured logic for obligation and permission, and insert that into the generation proce- 
dure instead. It goes without saying, of course, that the resultant set of consistent 
positions generated might well be quite different from those described in what now 
follows. 



3 Generating Normative-Informational Positions 

Given that the modality ‘I-’ is assigned the logic of a (relativised) normal modality of 
type K, there are precisely 4 informational positions for j vis-a-vis the state of affairs 
described by ‘A’. These are: 

(11) IjAa^Ij-A 

(12) \ r A A 

(13) — \ljA a — lly — A 

(14) IjAaIj-A 

It will be useful to introduce some phrases to refer to these positions: 

In (II), j is told straight truth/straight lie, depending on whether ‘A' is/is not the case. 
In (12), j is told straight truth/straight lie, depending on whether ‘—A’ is/is not the 
case. 

In (13), j is told neither ‘A’ nor ‘—A’, and in this sense (13) represents the silence 
position. 

In (14), j is told both ‘A’ and ‘—A’, and in this sense (14) represents the conflicting 
information position. 

In order to apply to (II )-(I4) the method for generating nonnative positions de- 
scribed in [4], enclose each of (I1)-(I4) in parentheses, then prefix each with ‘0 A ’ and 
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l O k —i\ respectively, to form 8 obligation expressions. Then prefix each of those 8 
expressions with the negation sign, and display the resulting 16 expressions as a list of 
8 tautologies: 

(1) O k (1/ a ily iA) v -,O t (1/ A -IpA) 

(2) 0 /( (IpA a ^T/) v -,O t (I pA A ^A) 

(3) O a (— iI^A a — ily — iA ) v — iO A ( — ilyA a —IpA) 

(4) () /( (1/ a TpA) v -,O k (I jA a Ij—A) 

(5) () /( — id^A a -J pA) v -nO k -,(IyA a —IpA ) 

(6) 0 /( — 4TpA a -IyA) v -nO k — iCIy — iA a -IyA) 

(7) () /( — ,1^4 A -IpA) v — iO A -<-IyA A -IpA) 

(8) O k -<IyA a IpA) v ^C) /( -flyA a IpA) 

There are 2 8 = 256 ways of selecting just one of the disjuncts from each of the dis- 
junctions (l)-(8). That is, 256 distinct conjunctions, each of 8 conjuncts, may be gen- 
erated from (l)-(8). It turns out that, of these 256 conjunctions, just 15 are logically 
consistent, given the logics selected for the component modalities. Each of these 15 
may be simplified, to remove redundant conjuncts (i.e., conjuncts that are themseves 
logically implied by some other conjunct in the same conjunction). The result may be 
exhibited as (N1)-(N15), below: 

(Nl) O k (IjA a IpA) 

(N2) O k (TpA a 
(N3) O t (-IyAA-IpA) 

(N4) O k (-djA v -IpA) a P k (-.1 jA a — Ty iA) a P k (-IjA a IpA) a P /( (IjA a -IpA) 
(N5) O k (IjA <-> — .IpA) a P /( (1/ a -IpA) a P A dpA a -IyA) 

(N6) P k IpA A P k (— .IpA A IjA) A P k (-.1 pA A -.IjA) 

(N7) P k IjA a P k (-IyA A IpA) a P /( (-nlyA A — iIpA) 

(N8) O k (IjA a IpA) 

(N9) O k IjA a P k (IjA a IpA) a P k (IjA a — .IpA) 

(N10) O k IpA a P k (IjA a IpA) a P k (Ij—A a -4^) 

(Nil) -, P /( (1/ A -IpA) a P k (Iy — lA a -IyA) a P t (-IyA A -IpA) a P k (IjA A IpA) 
(N12) P /( (IpA a -,I jA) a P A (Iy4 a —IpA) a P k (IjA a IpA) a P /( (-,1^4 a -Ip 4) 

(N13) P k (— ,1 jA A — ly A) A P k (IjA A IpA) A P k (IjA A — .IpA) A P k (IpA A -nljA) 
(N14) 0 A (IjA <-» IpA) a P A (1/ a IpA) a P k (-IyA a -IpA) 

(N15) P /( (1/ A IpA) a P /( (1/ a -IpA) a P A apA a -IyA) A p k (-IyA A -IpA) 
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4 Describing the Positions 

For the purpose of discussing (N1)-(N15), it is convenient first to split the group into 
two sub-groups, consisting of (N1)-(N7) and (N8)-(N15), respectively. Each of (Nl)- 
(N7) implies that the conflicting information position (vis-a-vis j) is not permitted for 
k. That is, each of (N1)-(N7) is incompatible with the truth of ‘P k (I jA a 1^— A)’ . By 
contrast, each of (N8)-(N15) implies that the conflicting information position (vis-a- 
vis j) is permitted for k. 

Note the correspondence between (N1)-(N7) and (E1)-(E7), ((Nl) to (El), (N2) to 

(E2), , and so on). The formal differences between each pair arise from the fact 

that the logic of the ‘E.’ modality contains the T. schema, which in turn implies the D. 
schema: 

EjA — > — Ej — A 

In other words, if the logic of the ‘I-’ modality had contained the D. schema, then 
each of (N1)-(N7) would have been reducible to forms that correspond exactly to 
those of (E1)-(E7), with (of course) ‘I-’ replacing ‘E-’ throughout, and ‘O k ’/‘P k ’ re- 
placing ‘O’/'P’ throughout, and some re-arrangement of the order of the conjuncts. 

Suppose now that ‘A’ is true. Then the positions (N1)-(N7) may be described as 
follows: 

(Nl) It is obligatory for k that j is told the straight truth. 

(N2) It is obligatory for k that j is told a straight lie. 

(N3) It is obligatory for k that the silence position obtains. 

(N4) The conflicting information position is forbidden for k, but the silence position, 
the straight lie position and the straight truth position are each permitted for k. 

(N5) The conflicting information position and the silence position are both forbidden 
for k, but the straight truth and straight lie positions are both permitted for k. 

(N6) It is not permitted for k that j is told a lie, but the straight truth and silence posi- 
tions are both permitted for k. 

(N7) It is not permitted for k that j is told the truth, but the straight lie and silence 
positions are both permitted for k. 

If, on the other hand, it is ‘—A’ rather than ‘A’ that is true, then (Nl) and (N2) 
swap descriptions, (N6) and (N7) swap descriptions, and the descriptions of each of 
(N3), (N4) and (N5) remain unchanged. 

It is the presence of (14) in the list of informational positions that gives rise to the 
normative-informational positions (N8)-(N15). (Clearly, there is no counterpart to 
(N8)-(N15) in the class of normative one-agent act positions just because the action 
counterpart to (14) is a logical contradiction.) 

Supposing, first, again, that ‘A’ is true, then the following descriptions may be pro- 
posed for (N8)-(N15): 

(N8) It is obligatory for k that the conflicting information position obtains. 

(N9) It is obligatory for k that j is told the truth; the straight truth position is permit- 
ted for k, but so is the conflicting information position. 

(N10) It is obligatory for k that j is told a lie; the straight lie position is permitted for 
k, but so is the conflicting information position. 
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(Nil) The straight truth position is forbidden (= not permitted) for k, but the straight 
lie position, the silence position and the conflicting information position are each 
permitted for k. 

(N12) The straight lie position is forbidden for k, but the straight truth position, the 
silence position and the conflicting information position are each permitted for k. 

(N13) The silence position is forbidden for k, but the conflicting information position, 
the straight truth position, the straight lie position are each permitted for k. 

(N14) The straight truth and straight lie positions are both forbidden for k, but the 
conflicting information position and the silence position are both permitted for k. 

(N15) The conflicting information position, the straight truth position, the straight lie 
position and the silence position are each permitted for k. 

If, on the other hand, it is .A’ rather than ‘A’ that is true, then (N9) and (N10) 
swap descriptions, and (Nil) and (N12) swap descriptions, but the descriptions of 
each of (N8), (N13), (N14) and (N15) remain unchanged. 



5 Some Observations about the Application of the Theory 

Given the choice of logics for the modalities, the generation method shows that - for 
any agents k (norm-bearer) and j (informee), and for any state of affairs ‘A’ - pre- 
cisely one of the set of 15 normative-informational positions holds. So the set may be 
used as a tool in the analysis of normative-informational concepts, such as the per- 
mission to be silent, and the permission to be correctly informed', furthermore, as is 
clearly indicated in the existing literature on normative positions, the method provides 
a means of approaching the representation of more complex structures, of the kind 
exhibited by Hohfeldian rights-relations; in the present context, the right to silence 
and the right to know would be interesting candidates for investigation. 

The present paper takes some preliminary steps in laying the formal-logical foun- 
dations for these kinds of conceptual analyses, but further details remain as the focus 
for future work. But, by way of illustration of how to proceed, consider the example 
‘permission to be silent ’ in relation to the set of 15 positions. In fact 8 of these 15 
contain or imply k’s permission to be silent, vis-a-vis j, with respect to ‘A’, and these 
are (N3), (N4), (N6), (N7), (Nil), (N12), (N14) and (N15). To define the context 
further, suppose that the concern is with the permission ordinarily granted to a per- 
son, under English Law, at the time of that person’s arrest for an alleged criminal 
offence 3 . Which of the 8 cases would be the appropriate choice? 

Well, it is reasonable to eliminate (N3) immediately, since k, the person arrested, is 
not under an obligation (as far as j, the arresting authority is concerned) to remain 
silent. There would seem to be good grounds for eliminating (N7), too, since it forbids 



3 The person arrested is ordinarily told that he/she has the right to remain silent, but that any- 
thing he/she says may be taken down and used in evidence against him/her. The right to re- 
main silent implies (but is not implied by ) the permission to remain silent, but the relational 
aspect, characteristic of the Hohfeldian interpretation of rights (rather than mere permis- 
sions), will be ignored for present purposes. It will most definitely figure in future work, 
however. 
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k to tell the truth, which again would not ordinarily be understood to be part of the 
arresting authority’s intention. Similar considerations would eliminate (Nil) and 
(N14). Then there remain the 4 positions: (N4), (N6), (N12) and (N15). Is the agent k 
forbidden , i.e., not permitted, to give conflicting information (as far as j is concerned), 
at the time of arrest (when he/she is not, one supposes, under oath),l If not, then (N4) 
gets eliminated, along with (N6). The final choice, between (N12) and (N15), depends 
on whether or not the straight lie position is permitted for k. 

As a second illustration, consider the situation of a future British government, led 
by P.M. Bliar, which is not permitted to be silent on the burning issue of the use, by 
the government, of weapons of mass deception. What might here be the normative- 
informational position of the government (k), vis-a-vis the citizen (j), as P.M. Bliar 
sees it? Clearly, the 8 positions considered above in discussion of the previous exam- 
ple, each of which contains or implies that the silence position is permitted, are ruled 
out. The positions (Nl), (N2), (N5), (N8), (N9), (N10) and (N13) remain. Given 
Bliar’ s aversion to straight truth, and the lack of subtlety of the straight lie, (Nl) and 
(N2) are eliminated. The transmission of conflicting information, being a valuable 
strategy for the spin doctors, is hardly going to be forbidden by Bliar and his magic 
circle, so (N5) goes out; but then perhaps they don’t want to tie themselves to the use 
of conflicting information, so (N8) is eliminated. Furthermore, supposing that they 
don’t want to be required to let the truth out, or required to lie, (N9) and (N10) go 
too. So (N13) remains as the Bliar position: ‘say what you like about ‘A’, so long as 
you say something’ ! 4 



6 Concluding Remarks 

Two points, in conclusion: First, Marek Sergot has indicated to me that there is also 
another point of departure for the generation of normative-informational positions, 
taking not the 4 positions (I1)-(I4) as the base, but rather the 8 positions obtained by 
conjoining each of those positions with ‘A’ or ‘—A’. This is clearly an option worthy 
of further investigation, although the inclusion of 'AT— A' within the scope of the 
deontic operator, in generating the normative-informational positions from this base, 
will perhaps not always produce interesting results, since the question of whether or 
not ‘AT— A' is itself obligatory may be quite irrelevant. By contrast, the approach 
taken above first generated the normative-informational positions, and afterwards 
considered the truth/falsity of ‘A’. 

Secondly, discussion of the application of this formal framework would greatly 
benefit by taking a range of concrete examples - from the Law, or from other types of 
existing regulations - where the point of the rules is to define a policy to govern the 
transmission of information. The merits and shortcomings of the present formal 
framework could then be given a more thorough assessment, by measuring the extent 
to which it exposes, or not, the details and nuances exhibited by those rules. 



4 This example, despite being facetious, does nevertheless serve to illustrate the way in which 
a map of the class of possible positions might play a role in choosing (for good or ill) an ‘ap- 
propriate’ strategy or policy. Prolegomena to the theory of spin ? 
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Abstract. We use non-Kripkean quasi-matrix semantics for the formal- 
ization of the systems 83 ^, S^dp and S 3 d q of deontic logic. The sys- 
tem S3 d is weaker than the standard logic SDL. The semantics for 
S3 dp represents combination of quasi-matrix semantics and the seman- 
tics of truth value gluts, which allows S3 dp to avoid deontic explosion 
OA A 0 ~iA D OB. The system S3d g rejects both deontic explosion and 
the formula OA A O ~<A D OAA-iOA, thus it allows to consider deontic 
dilemmas without classical contradictions. 

The systems S$d, S5 dp and S5 d q in which the two types of deontic oper- 
ators are used, namely, strong and weak obligation (permission), can be 
built as an extension of the correspondent systems S3d, S3 d P and S3 d q - 



1 Quasi-Matrix Semantics for Modal Logic 



Since the classical paper of Georg Henrik von Wright [19] deontic logic is con- 
sidered as a special branch of modal logic. The so called standard deontic logic 
(SDL) can be obtained from the normal modal logic KD (system name is taken 
from B.Chellas [3]) by replacing the usual operators of necessity and possibility - 
respectively, box and diamond - by the “normative” operators, correspondingly, 
O ( is read as it is obligatory that, or it ought to be that), and P (it is permissible 
that ) . 

The system SDL contains all tautologies of classical propositional logic and 
the following axioms: 



(SDLA1) O (p D <?) D (Op D O q)- 
(SDLA2) Op D Pp; 

(SDLA3) Pp = 

Inference rules: 

(SDLf?l) Modus ponens ; 
(SDLA2) 



d e f 

Operator F (it is forbidden that) can be defined as Fp = ->Pp. 

Semantics of SDL is based on the well-known Kripke model M = (S,tt,R), 
where S' is a set of possible worlds, tt is a truth assignment function assigning 
truth to the primitive propositions per each world, and R C S x S is a relation 
relating with each world a set of alternative worlds. Given a Kripke-model M 
and a world s € S, the modal operators are defined as follows: 



A. Lomuscio and D. Nute (Eds.): DEON 2004, LNAI 3065, pp. 191—208, 2004. 
(c) Springer- Verlag Berlin Heidelberg 2004 
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(M, s) |= Op iff Vf (A(s, t) =► (AT, t) (= p) 

(M, s) |= Pp iff (i?(s, t)&(M, t) |= p) 

(M, s) |= Fp iff Vf (7?(s, t) =>• (Af, t)-> f= p) 

J. Kearns ([12]) and Yu. Ivlev ([11]) in different ways suggested an idea of 
modal semantics which is completely different from Kripke-style semantics in 
that it does not use the idea of possible worlds. Instead of the alternative 
worlds one deals with the alternative interpetation quasi-functions formed by 
the given interpretation function ([11]). This approach allows to give table defi- 
nitions for modal operators; there sometime can be vagueness in evaluations of 
modal formulas- in that case the value of the given formula A is considered to 
be “undetermined”, “alternative”- for instance, the value p/q means “either p, 
or q” . Instead of an interpretation function, interpretation quasi-function takes 
only one single value from the fraction; in case of the value p/q there are two 
alternative quasi-interpretations, one in which A takes the value p, and the other 
in which A takes q. The formula A is true in the interpretation if and only if it 
is true in each alternative interpretation caused by the given interpretation. 

The advantage of using quasi-matrix approach is that on its basis it is pos- 
sible to consider the wide range of modal systems, which seems to include as 
a subset all known Kripkean modal logics and contains even more “interme- 
diate” systems, for example the ones weaker then K, T, B, S4, etc. (some of 
that four valued modal systems were suggested in [11]). One can expect that 
the application of quasi-matrix approach to deontic logic can promote consid- 
eration of some additional aspects of deontic matters. Another good point of 
quasi-matrix semantics is that it allows to define the properties of modal (deon- 
tic) logic under construction beforehand, just in the table definitions of modal 
operators. In particular, in the described below systems there is an opportunity 
to consider separately the properties of the action sentences (acts) and to en- 
ter special deontic connectives by means of which the complex acts are formed. 
The properties of deontic connectives are set by table definitions in accordance 
with the preliminary informal discussions about the character of action of that 
connectives. 

The considered below deontic system S 3 d represents modification of tlrree- 
valued quasi-matrix deontic logic suggested in [ 11 ] and is weaker than the stan- 
dard deontic logic SDL, because the axiom SDLA1 the rule SDLi?2 are no 
longer valid in 83 ^. In the next part we bring the intuitions on the system 83 ^. 

2 Intuitions 

First of all, the distinction between terms and formulas of deontic system 83 ^ 
has the same motivation as it was given in logic for normative propositions [ 1 ] 
which has been constructed on the basis of possible- world semantics. The reason 
for such distinction is that “deontic operators require as operands descriptions 
of actions (action sentences) but once deontic operator is applied to an action 
sentence the resulting deontic sentence is no longer a description of an action 
but a normative qualification of the action described by the action sentence 
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contained within. Hence the occurrence of a deontic operator within the scope 
of another deontic operator makes no sense” ([ 1 ], p. 47 ). 

Now let us speak about the intuitive meaning of the connectives for the 
acts *, ®, ®. The act p* means the abstention from the act p. An interesting 
discussion of what the abstention from the act does mean could be found in the 
papers of Wright, but from the point of view of deontic values one could say 
definitely that if the act p is obligatory at some code, then the abstention from p 
should be forbidden by that code, and the same reasoning when p is forbidden. 
If p is indifferent then it seems like p* should also be indifferent. Thus our table 
definition for the act p* is consistent with the intuition. 

The act (p®q) means consecutive or parallel performance of actions p and q. 
Note that the act {p®p) has different meaning than the act p, since it could stay 
for the consecutive performance of the acts p and p (or, for the recurrence of p) 
which in general case is not the same as p. The abstention from the act ( p ® q) 
intuitively would mean the abstention from at least one of the acts p , q. So it 
seems intuitively reasonable to keep such equalities as (p ® q)* = p* ® q* , thus 
the order of values u/v/w in table definitions for ® and ffi is important. 
In other words, one can’t take arbitrary combinations of quasi-matrices for ® 
and ®: given the two correspondent alternative values u\/v\/w\ and U2/V2/W2 
in tables for ® and ®, the only three quasi-interpretations are admissible: one 
in which u\ in table for ® corresponds to U2 in table for ®, and the other two 
with the same correspondences v\ to V2 and w\ to W2 ■ In fact, the tables for the 
system S3 d defines 6 different quasi-interpretations. 

The act (pffi q) means either performance of the act p, or q, or (p< 8 > q). The 
act ( p ® p) can be understood as an abstention from the act (q ® q), if p = q* , 
that is to abstain from recurrence of the act <7, one should abstain from the first 
or from the second performance of the act q. 

Now let us give some intuitions for choosing the alternative truth values that 
are given in the table definitions. 

• The term (p® q) takes the value o/i/b- “either obligatory, or indifferent, or 
forbidden ” when both acts p, q are evaluated as obligatory. Let p and q are the 
two different acts. Intuitively, if each of the different terms p, q is obligatory, 
then the act (p®<7) should also be obligatory. We assume here that the normative 
code must be consistent in itself and in its relation to other codes with which 
it submits. For, assume that an agent (suppose, a spy) would be obliged (p) 
to fill her automobile with petrol at 2 o ’clock and ( q ) to smoke a cigarette at 2 
o’clock (as a secret sign for somebody), but the whole act (p ® q) is forbidden 
at least at filling station, thus it is forbidden in the instructions for the spy (in 
order not to conflict with the environment). Now, since we have F(p® q) = O 
( p®<7 )* = O (p* ® q*), we would have an obligation for the agent to abstain from 
filling her automobile or from smoking her cigarette and at the same time the 
agent is obliged to fill her automobile and is obliged to smoke a cigarettel Such 
code would be inconsistent. Similar examples could be brought to illustrate the 
case when the terms p and q both take the value obligatory , and the term p ® q 
is indif f event - again, it would lead to inconsistency of the considered code. 
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A little bit different situation occures in case of the act (p <g> p) . If the act p 
is obligatory at some code then nothing could be said about its recurrence - 
suppose, a spy is obliged per the certain day to visit some agreed place. However 
visiting by the spy per the same day of the same place secondarily could be 
indifferent or even forbidden (and obligatory as well) in spy’s instructions. Thus, 
in general case we take it that for the two obligatory acts p, q, the act {p (g> q) 
takes the value o/i/b. 

• The term (p ® q) takes the value i/b when both acts p, q are evaluated as 
indifferent. Again, let p and q are the two different acts. The case when the 
term (p <g) q) takes the value i when both acts p, q take this value, is trivial: let, 
for example, p be to seat on the bench and q be to read the newspaper- both 
acts are indifferent in some normative code, and so is the complex act ( p®q ). 
But if an agent decides to fill her automobile with petrol at 2 o ’clock (the act p 
which is indifferent in some code) and to smoke a cigarette at 2 o ' clock (the act 
q which in itself is also indifferent in the same code), then the act (p (g> q) is of 
course forbidden! Or even consider the act (p®p*)- to fill the automobile with 
petrol at 2 o’clock and to abstain from it at 2 o’clock - this act is impossible, 
thus it must take the value forbidden at our system. The act ( p (g> p) for the 
value indifferent of p also takes the alternative value i/b. Suppose, the act p 
is to take a free cup of coffee, and the rules of some cafe allow to take the first 
cup of coffee for free, then the performance of the action p is indifferent while 
the action (p®p) is forbidden in the rules of that cafe. Another value is trivial. 

Can the term (p ® q) take the value o - obligatory - in case when both acts 

p, q are indifferent ? Would it be correct to bring an example that a man is 
obliged to take off his shoes (q) when entering the house ( p ) (both acts p, q are 
indifferent )? The answer is no since that example represents not the act (p®(?) 
but the conditional {p H > q) which could take the value o in case when p and 
q both take the value i. Otherwise we would have for the agent the obligation 
to enter the house and to take off his shoes. If the acts p, q are both indifferent 
at some code, then how could it be that the consecutive or parallel performance 
of that acts is obligatory in that code? Since we are allowed to abstain from 
any of the acts p, q (because they are indifferent), then how could we keep the 
obligation to fulfil them both? In a similar way, if p is indifferent, then how could 
the recurrence of p be obligatory? Thus we take it that {p <g> q) can’t take the 
value obligatory when p, q are both indif ferent. 

• In a similar way we discuss the alternative value b/i/o for the term (p ® q), 
if both acts p and q take the value b. If p, q are the two different forbidden 
acts, then (p ® q) seems to be forbidden as well, because if p and q are both 
forbidden, then how could it be that the act at least one of p and q is allowed? 
Now, consider the act (p ® p). As we told, if p = < 7 *, then the most probable 
intuitive meaning for the act (p ® p) is the abstention from recurrence of the act 

q, (q<S>q), otherwise (p®p) should have the same meaning as p. Therefore, if the 
recurrence of some obligatory act q is either obligatory, or is indif ferent, or, 
at last, is forbidden, then the abstention from that recurrence, (p®p), should 
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be either forbidden, or is indif ferent, or is obligatory , just when p takes the 
value b. So in general case the alternative value for the term (p© q) is b/i/o. 

• The term (p © q) takes the alternative value i/o, if both acts p and q take 
the value i. Consider again the two different acts p, q. The case when the act 
(p© q) is indifferent if both acts p, q are indifferent, is trivial. Now suppose that 
the agent is obliged (by some code) to deliver the letter to the addressee, and 
suppose the agent has few alternatives to reach the addressee (by choosing the 
road, transport, etc.) The choice of the concrete alternative is indifferent from 
the point of view of the given code. Nevertheless, the whole act is obligatory for 
the agent. In case of the act (pffip), if p = q* , then we have again the abstention 
from the act (q <3 q), which takes the value i/b, thus the value of (p © p) is i/o. 

Can the term (p © q) take the value b - forbidden - in case when both acts 
p, q are indifferent ? Again, intuitively, if both acts p, q are allowed, then how 
could it be that the act at least one of p and q is forbidden, or, is not allowed? 
Thus, we take it that in this case (p © q) can’t take the value b. 

3 Quasi-matrix Deontic Logic S 3 d 

The semantics QM 3d is defined in a following way. 



Language 

The language L^d of three-valued quasi-matrix logic contains: 

• p, q, r,... - variables for the atomic action sentences (acts); 

• ®, ©, * - connectives for the acts, correspondingly is read “and”, “or”, “it is 
not the case that” (“abstention from...”); 

• O, P- operators, correspondingly is read “it is obligatory that” and “it is 
permissible that”; 

• -i, A, V, D, = - logical signs for negation, conjunction, disjunction, material 
conditional and material biconditional; 

• brackets. 



Formation Rules 

1. Definition of a term : 

• Every atomic action sentence is a term; 

• if p and q are terms then p* , (p © q),(p © q) are also terms. 

2. Definition of a formula: 

• if p is a term then Op and Pp are the formulas; 

• if A and B are the formulas, then also are -i A, (A A B), (A V B), ( A D B), 
(A = B). 
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3 . Definitions of the connectives for the acts: 

The variables for the acts take values from the field {o, i, 6}, correspondingly is 
read obligatory, indifferent, forbidden. 

<S> o i b ® o i b 

p o i b o o/i/b * i b o o o o 

p* b i o i i i/b ** b i o i/o ** i 

b b b b b o i b/i/o * 

Rem. The value u/v/w is read “either u, or v, or w” . It means that in fact there 
are several alternative quasi- matrices for each of the connectives © and ®, in 
which one chooses the only one value from the “fraction”. But one can’t take 
the arbitrary combinations of values: the only admissible quasi-matrices for ® 
and © are those with the same positions of the values in fractions marked with 
• or with if, say, there is a quasi-interpretation in which \p\ = \q\ = b iff 
\p®q\ = b, then the same quasi-interpretation function assigns \p\ = |g| = o iff 
\p ® q\ = o. 

Rem. One could define also deontic conditional p H > q as a term p* © q. 

4 . Definitions of the operators O, P: 

p Op Pp 

0 t t 

1 f t 
b f f 

The formulas take values from the field {t, /} (true, false). The definitions 
of the connectives -i, A, V, D, = are given as usual. 

For the formula A of the system S3 d we define an interpretation function 
| • | for the terms and for the formulas in accordance with the above described 
table definitions. The “alternative” value u/v of the act means that this value is 
fixed but undetermined (“either u, or i>”). The alternative interpretation quasi- 
function || • ||, caused by the function | • |, maps the formula (term) V to the only 
one single element from the fraction; thus if the “fraction” contains m alternative 
values then we get in alternative interpretations of V . 

The formula A is valid in the given interpretation (we will write |A| = t ) if 
and only if (iff) it takes the value t in each alternative interpretation caused by 
this interpretation (||A||fc = t for every 1 < k < m, m is a number of alternative 
interpretations); A is satisfiable in the given interpretation iff it takes the value 
t in some alternative interpretation caused by the given interpretation; A is 
satisfiable in semantics QM 3d iff it is valid in some interpretation; A is valid in 
semantics QM 3d iff it is valid in each interpretation. 

The result of the formalization of the described semantics is the system 83^. 

The system 83^ 

(S 3c iA 0 ) All tautologies of classical propositional logic, 

(S 3 d Al) Op = Op**; 

(S 3 d A 2 ) Pp = Pp**; 
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( S 3d^ 3 ) °(p © o) = °(p* © ?*)*; 

(S 3d A4) 0(p®q) = 0(p*®q*)*-, 

(S 3d A5) P(p®q) = P(p*®q*)*-, 

(S 3d A6) P(p®g) = P(p*®g*)*; 

(S 3d A7) Op D P p; 

(S 3d A8) Op = -P p*; 

(S 3d Al9) 0(p ® q) D Op A Oq; 

(S 3d A10) P (p ® q) D Pp A P q; 

(S 3d All) Op V Oq D 0(p ® q); 

(S 3d A12) PpVPqD P (p © q); 

Inference rules: 

(S 3 d-Rl) Modus ponens for the formulas; 

(S 3( jf?2) Substitution rule for the terms and for the formulas. 

Definitions: 



(Fp is read it is forbidden that p); 

• Ip Pp A P p* 

(Ip is read it is indifferent that p). 



Theorem 1.3. The system S 3g( / is sound and complete with respect to semantics 

QM 3 d- 

Sketch of the Proof: 

Soundness can be proved by showing that each axiom is valid in each interpre- 
tation, since it is true in every alternative interpretation of every given inter- 
pretation. Suppose, for example, that the axiom (S 3d T10) is not valid. That 
means that there is an interpretation function | • \ v in which (S 3d T10) is not 
valid, so there is an alternative quasi-function || • ||„/, derived from | • |„ s.t. 

1 1 P(p © q) A PpAPq\\ v f = /, so ||P(p®g)||„' = t and ||PpAP<?||„/ = /. It 
follows that either ||p® q\\ v > = o, or ||p® q\\ v > = i, thus according to table 
definitions neither \\p\\ v ' = b nor ||<?||,/ = b . But at the same time, ||Pp||„/ = / 
or ||P<z||„' = /, so ||p||„' = b or ||g||„' = b. Therefore, we get the contradiction. 
The rules S 3( jl?l and S 3 df?2 do preserve validity of the formulas. 

To prove completeness, one has to prove the two additional lemmas. 



Lemma 1. The set of formulasQ which is consistent with respect to S 3d can be 
extended to a maximal consistent set T which has the following properties: 

1 ) for each term p either Pp A Pp* € T, or Op € T, or -SPp £ T; 

2) if T b B and T CT then B £ T; 

3) B £ T or C £ T if and only if B V C £ T; 

4) ~^B £ T or C £ T if and only if B D C £ T. 

Let us prove for example the statement 1 ). The extension of the given set 
of formulas Q to a maximal consistent set T could be shown in a usual way. 
Let Bi,B 2 ,— be some sequence of formulas of S 3( j and let Q be a set of for- 
mulas which is consistent with S 3( j. We construct a sequence of sets of formulas 
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To,Ti,T 2, ... in a following way. Let T 0 = Q and suppose that the set T n is de- 
fined. If the formula B n+ 1 is not derivable from T n , then T n+ \ = T n U {-<B n+ i}\ 
if B n+ 1 is derivable from T n , then T n+ 1 = T n . Let T be a union of all sets T). For 
the proof of consistency of T, one could show by induction the consistency of 
each set XL By construction of T, for each formula A either A £ T, or ->A £ T. 
Therefore, in our system, for the given term p, 

(o) {either Op £ T, or ->0 p £ T} and {either Pp £ T, or ->P p £ T}, 
from which one could obtain the statement 1 ) using the correspondent axioms 
of S3 d (the cases when the formulas represent boolean combinations of Op and 
Pp can be easily reduced to (o)). 

Lemma 2. There is a function\ ■ |t such that it possesses all the properties of 
an interpretation function, and for each formula A, \A\t = t A £ T . 
Consider the function | • \t possessing the following properties: 

• \p\t = o <t=> Op £ T; 

• \p\t = i ^ P p A Pp* £ T ; 

• \p\t — b <t=> -iP p £ T; 

• \A\t = t <£> A £ T (A is a formula). 

It can be shown that the function | • |t possesses all the properties of an 
interpretation function for logic 83^. Let us show some steps of the proof of 
lemma, for example, let us prove that if \p\t = b , then \p*\t = o. Suppose, 
|p|t = b, thus, according to definition of | • |t, -| P p £ T. By (S 3d A2) and 
(S 3d A8), -iP p = ^Pp** = Op*, thus Op* £ T, and therefore, |p*|r = o. Now 
let us show that if \p\r = |g|r = i, then | p <g) q\ t is either i or b. Suppose 
|p| T = |g|r = i, then by definition of | • |t, Pp £ T , Pp* £ T and P q £ T, 
P q* £ T. By (S 3d A8), Pp* b ^Op, P q* b -nOq. Thus ^Op £ T, -nOq £ T. 
Suppose now, that | p® q\r = o, then O(p0 q) £ T, and, by (S 3d A9), Op £ T 
and Oq £ T, and we get a contradiciton, which in its turn contradicts to the 
fact that the set T is consistent. Thus \p®q\r is either i or b (but not both i, b , 
because that would make T inconsistent). The other steps could be shown in a 
similar way. 

Let us make the last steps of the completeness proof. Suppose there is the 
valid formula E which is not provable in 83^. Therefore, the formula ~^—>E is also 
not provable in 83^- The set {~<E} is consistent with S 3 d, it can be extended to 
the maximal consistent set of formulas T by lemma 1. There is an interpretation 
| • |r in which all the formulas from T are valid (lemma 2), hence ~^E is also 
valid (in this interpretation). Thus the formula E is not valid in | • |t, but this 
contradicts to the assumption. □ 

Example. Let us show that the formula of SDL, ->0 (p®p*) ( No contradictory 
obligations), is valid in quasi-matrix semantics. Take an arbitrary interpretation 
| • |,j and show that | ^0(pg)p*)|^ = t. That means that | |^0(p (g) p*)||,y = t 
for all alternative interpretation quasi-functions, || • Hy, derived from | • |^. So 
consider any such || • ||y and suppose for reductio that ||^0(p ® p*)||^' t. 
Hence ||0(p 0 p*)||#' = t , and so ||(p®p*)||,y = o. From this one can move 
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immediately to ||p||^' = o and ||p*||^' = o, so that \\p\\$> = b, a contradiction, 
and we are done. 



4 Semantics of Truth Value Gluts 

In addition to the plausible need to allow for the possibility of moral dilemmas, 
which requires rejecting the formula ->(OpA O ->p) of SDL, one must also reject 
the thesis (*) Fsdl ( OA A 0~>A) D OB, since that would mean that if an 
agent finds herself in a moral dilemma, then she ought to do everything, which 
is surely going too far. Yet this formula, (*), is a theorem of SDL, as follows. 
Consider the theorem I- S dl (A A ->A) Z> B. Application of the rule (SDLR2) 
gives b sdl 0{{A A ->A) D B), from which by SDLA1 one infers Fsdl 0(A A 
-i A) D OB, and, combining with theorem of SDL 0(p A q) = Op A O q , we get 
(*) b sdl (OAaO-iA) D OB. Notice that this argument rests on the premise of 
classical logic that a contradiction implies everything. 

Different approaches were suggested to avoid this and some other “unde- 
sirable” theorems in monadic deontic logic. J.Horty [9] suggests an approach 
based on nonmonotonic logic. Some authors consider various modifications of 
Kripke-semantics, for example, “two-plrase approach” of L.W.N. Van der Torre 
[17], “preference-based deontic logic” of S.O.Hansson [8], “multiplex semantics” 
of L. Goble [6], non-kripkean deontic logic of P.Sclrotclr and R. Jennings [16], se- 
mantics of FUSION logic of L.Clrolvy and F.Cuppens [4]. 

One way to avoid the paradoxical theorem (*) is to consider relevant implica- 
tion instead classical one, since the theorem (A A -> A) — > B is no longer valid in 
logic with relevance. The idea of combination deontic principles with the princi- 
ples of relevant logic was discussed in different forms (for the brief overview see 
L. Goble [7], in which the author also constructs various systems of monadic and 
dyadic relevant deontic logic as an extension of the Anderson-Belnap system R 
of relevant implication). 

We now propose another approach based on applying our quasi-matrix se- 
mantics for deontic logic to a basic paraconsistent logic whose semantics allows 
for truth value “gluts”, the possibility that some formulas might be both true 
and false. This will produce the deontic system S3 dp which does not contain the 
undesirable theorem (*). The approach is based on the notion of partially defined 
predicates. The idea of generalization of traditional versions of completely de- 
fined predicates and sets by considering partially defined predicates and sets was 
investigated in various forms in the papers of T.Scolem, G.Beman, D.Boclrvar, 
V.Akkerman, K.Schiitte, F. Fitch, S.Feferman and some others. H.Wang ([18]) 
suggested two systems of the calculus of partial predicates, PP and EP, propo- 
sitional fragments of these systems were formalized by A. Rose ([15]) and by 
N. Ermolaeva ([5]). 

We would be primarily interested in semantics with truth value “ gluts' ’ ( 
or paraconsistent semantics) TGI and in its corresponding system G since we 
expect to obtain deontic system which is normatively paraconsistent in that it 
would not allow, for example, the theorem (Op A Op*) —rOq and at the same 
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time normatively complete such that each action sentence p has its deontic es- 
timation. But of course there could be constructed another deontic systems, 
namely, normatively pseudocomplete but consistent, or both, normatively pseu- 
docomplete and paraconsistent. 

Let us describe the semantics TGI. Let v be an assignment function as- 
signing to each formula A a subset of {truth, false}. We want the truth value 
gaps to be excluded, that can be done by requiring that v{A) not be empty. We 
will say that the formula A is true in TGI (u t (A)) if and only if t € v(A), and, 
similarly, A is false in TGI (vf(A)) if and only if / G v{A). 

The evaluations for the formulas containing -i, A, V, D are the following: 
v t hp) iff Vf (p) v f (->p) iff v t {p) 

v t (p A q) iff v t (p) and v t {q) vj(p A q) iff Vf(p) or Vf(q) 
v t (pM q) iff v t (p) or v t (q) Vf{pM q) iff Vf(p) and Vf(q) 
v t (p D q) iff Vf(p) or v t (q) Vf(p D q) iff v t (p) and Vf(q) 

The formula of the type A — > B is valid in TGI if and only if vt(A) C vt(B). 
We note that none of the formulas which does not contain the connective — > 
is valid. 

Below is the axiomatic system which formalizes semantics TGI. 



The System G 

(GA1) A->AVB; 

(GA2) iVB->5Vl; 

(GA3) AAB^A- 
(GA4) AAB^BAA- 
(GT5) —i— i A -a A\ 

(GA6) A -a ~^—iA', 

(GA7) A A {B \/ C)^ A ABM A AC] 
(GA8) ■•'( .1 A B) -a —iA V —<B] 

(GA9) —i A V —>B -a —<(A A B)\ 

(GA10) -^{A V B ) -a —iA A ~>B\ 

(GA11) -<A A —<B -a —i {A V B)\ 

(GA12) B ^ A\/ -i A 



Inference Rules 

GR1 If A -A C and B -A C, then AM B -A C 
GR2 If A -a B and A -a C, then A-aBaC 
GR3 If A -> B and B C, then A -a C* 

GR4 If formula A contains propositional variable v, and formula B does not 
contain -A, then C is a result of substitution in A of all occurrences of v 
for B. 

A, B, C contain no connective -A . 

Theorem 1.4. (A. Rose [15], N. Ermolaeva [5]) Lq A -A B if and only ifvt(A) C 

MB). 
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5 Quasi-matrix Deontic Logic with Truth Value Gluts 



We adapt this method to quasi-matrix three- valued deontic logic, here we use 
the language L 3d of system S 3d . Now let v be an assignment function assigning 
to each action term p a nonempty subset of {o, i,b} and to each formula A a 
nonempty subset of {t, /}. Let’s define the valuation function v: 



(Df 5.1) 
(Df 5.2) 
(Df 5.3) 
(Df 5.4) 
(Df 5.5) 

(Df 5.6) 
(Df 5.7) 

(Df 5.8) 
(Df 5.9) 



(Df 5.10) 

(Df 5.11) 

(Df 5.12) 
(Df 5.13) 



t G v(Op) iff o € v(p), let us write it as v t (0 p) iff v 0 (p) (p is a term); 
Vf(Op) iff Vi(p) or v b {p)\ 
v t (Pp) iff v a (p) or Vi(p); 

Vf(Pp) iff v b (p); 

Vk(p*) iff V 4 -k(p) (k G {o,i,b}), here and below (1) stands for o, (2) 

- for i and (3)- for b; 

if v 0 {p< 8 > q) then v 0 (p) and v 0 (q)\ 

if Vi(ptg>q) then {v 0 {p) and v 0 (q)} or {v 0 (p) and u,(g)} or {vi(p) and 
v 0 (q)} or {Vi{p) and w* (<?)}; 

if v b (p® q) then v b (p) or v b (q) or {vi{p) and u,(g)}; 

if t >i(p) and v m {q) then Vk(p< 8 >q), where k = ma x.(l,m) except the 

cases l = m = o and l = m = i : 

if v 0 (p) and v 0 {q) then v 0 (p®q)/vi{p®q)/v b {p®q) (either v 0 {p®q), 

or Vi(p® q), or v b (p® q)); 

if Vi(p) and Vi(q) then v. t (p <g» q)/v b {p <g) q); 

if v 0 (p © q) then v 0 (p) or v 0 {q) or {vi(p) and Vi(q)}or {v b (p) and 

(<?)}; 

if Vi (p © q) then {vi(p) and u;,(g)}or {v b (p) and Vi(q)}or {vi(p) and 
w i( < ?)}° r {v b (p) and v b {q)}\ 
if v b (p® q) then v b {p) and v b {q)\ 

if Vf(p) and v m (q)) then v b {p® q), where k = min (l,m) except the 
cases l = m = b and l = m = i : 

if v b (p) and v b (q) then v b (p © q)/vi(p © q)/v a {p © q); 
if Vi(p) and Vi(q) then u^p © q)/v a (p © g); 

and the same valuations for the formulas ~<A, Af\B , A\J B and A D B 
as in semantics TGI. 



The example of using the above definitions will be given in a soundness proof 
of the system S 3 dp . 

Consider the alternative valuation quasi-functions v l , each of which takes 
only one single value from fractions in definitions (Df5.9) and (Df 5.13). Formula 
A — > B is valid in semantics SP 3 D if and only if, for each i, if t G v l (A), then 
t G v l (B) (1 < i < n, n is a number of valuation quasi-functions). We will write 

hsp 3 D A ^ B d = Vi(vi(A) c v\{B)). 

The system S 3d p represents the axiomatization of semantics SP 3 D. 
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The System S3 dp 

(S 3( z p A0) All theorems of system G; 

(S 3dp Al) Op o Op**; 

(S 3dp A2) P p o P P **; 

( S 3 d P A3 ) °(p °(p* © 9*)*; 

( S 3 d P A4 ) °(P © 9) ^ 0(p* 0 q*)*; 

(S 3dp A5) P(p 0 q) o P (p* © q*)*; 

(S 3dp A6) P(p®?)f> P(p* 0 q*)*; 

(s 3 d P A7 ) °p p p; 

(S 3dp A8) Op o -P P *; 

( S 3 d P A9 ) °(P © 9) Op A Og; 

(S 3dp A10) P(p ® q) -A Pp A Pg; 

( S 3d P ^ u ) °P v °9 °(P © «); 

( S 3d P ^ 12 ) Pp V Pq -> P(p © q); 

Inference Rules 

(S 3dp R0) Rules of system G; 

(S 3dp M) f. 

Substitution rule for the terms: if formula A contains atomic term p, and q 
is an arbitrary term, then C is a result of substitution in A of all occurrences of 
V by q. 

Rem. A o B stands for “A — > B and B — > A” . 

Operators F and I (correspondingly, it is forbidden that and it is indifferent 
that) could be defined. 

Theorem 1.5. |=sp 3 d A — > B <^> \- 3dp A — >• B. 

Proof: Soundness follows from the fact that, for each axiom (S 3£ ; P A0 — S 3 d p A12) 
of the type A — > B, v t (A ) C v t {B). Since, by (Df.5.5), vffp**) iff Vk(p ), then the 
axioms (S 3dp Al) and (S 3dp A2) are valid. Then, since in each quasi-interpretation 
a £ (p 0 q) iff cr £ {{p* © q*)*) for any deontic value a (that follows from 
definitions by considering separately each quasi-interpretation) , then the axioms 
(S 3qd A3) and (S 3qd A5) are valid. By the same reasons, since a £ (p © q) iff 
a £ (p* 0 q*)*, then the axioms (S 3dp A4) and (S 3dp A6) are valid as well. Now 
let’s show for example the validity of the axiom (S 3dp A9). Suppose, it is not 
valid, therefore there must be quasi-interpretation v' s.t. t £ v'(O(p0 q) would 
not imply t £ v' {Op A Oq), or, t £ v'(0 (p0q) and / £ v'(Op A Oq). Therefore, 
o £ v'{p0q) and {i £ v'{p) or b £ v'{p) or * £ v'{q) or b £ v'{q)}. By definitions, 
there are quasi-interpretations v° in which o £ v°{p 0 q). But o £ v°{p 0 q) in 
such interpretations implies o £ v°{p) and o £ v°{p), and we get contradiction. 
The inference rules do preserve the validity of formulas. 

For the proof of completeness, assume that there is the formula A — > B, such 
that t ’t(A) C i>t(B), which is not a theorem of S 3 dp (or -\ A —> B). Since formulas 
A and B do not contain the connective one could present these formulas 
in the disjunctive normal form (DNF) by using the G-theorems GA4-GA11, 
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the substitution rule GR4 and the derived rule DR1 : If F — » G and A o B, 
then F' —> G' , where F’, G' are formulas obtained from F and G by replacing 
some occurences of A by B. 

Now let us have the formula A — > B, which is not a theorem, and at which 
both A and B are presented in DNF, namely, 

H d A V d 2 A V ... V d A —> d B V d B V ... V d B . 

Using the rule GR1, we get 

H d\ — > d B V ... V d B , or H d A — > d B V ... V d B , or... ,or H d n A — > d B V ... V d B . 
Then, using the derived rule DR2 : If A —> B, then A — ► B V C, we get for 
each j (1 < j < m) 

H d\ — > d B , or H d\ — > d B , or..., or H d A — > d B . Let us take H d k A — > d B for 
some fixed k. 

On the other hand, by assumption, v t {d\\/ ...V dlff) C v t (d B \/d B \/...\/d B ). 
It follows that Vt(d‘ A ) C v t (d B V d B V ... V d B ) for each i, 1 < i < n. There could 
be two possibilities. 

Case 1. For every * (1 < i < n), there is j (1 < j < m), such that v t (d l A ) C 
v t (d B ), and 

Case 2. There is i (1 < i < n), such that for every j (1 < j < m), Vt(d l A ) % 
v t(d B ). 

Consider the case 1. Let us have the disjuncts d A , d J B such that Vt(d A ) C 
Vt(d' B ). In accordance with the above reasoning, 

H d A — > d° B . The disjunct d A , as well as the disjunct d B , represents con- 
junction of modalized formulas O piA O P 2 A ...A O p v A P p v + iA P p v + 2 A ...A 
P p v + w , where the symbol 0 means that operator 0 has been taken either with, 
or without negation, and pi,p 2 , ■■■,Pv,Pv+ 1 , ■■■■ > Pv+w are arbitrary terms. 

Using the theorem S3dpA7, the rule (DR1) and the axioms of G, one could 
present this conjunction such that each conjunct would represent either the 
formula Opi, or the formula P pj (1 < i,j < v + w). 

Therefore, for the formula ~t d A d B we would have 

H Opx A Op 2 A ... A O p v A Pp„ + iA Vp v+2 A ... A P p v+w Ori A O r 2 A ... A 

Or# A Pr# +1 A Pr# +2 A ... A Pr# +p . 

Using the rule GR2, we get 

(o rl ) H Opi A ... A Op v A Ppv+i A ... A P p v+w -» Ori, or 

(o r2 ) H Opi A ... A Op v A Pp t ,+i A ... A P p v+w -4 Or 2 , or 

,or 

(o r #) H Opi A ... A Op v A Pp. u+ i A ... A Pp„ +U , -A Or#, or 

(o r # +1 ) H Op 1 A ... A O p v A Pp v+ i A ... A P p v+w -4 Pr# +1 , or 

, or 

(o r # +p ) H Opi A ... A O p v A Pp„+i A ... A P p v + w P r# +p . 

Let p C q means that either p = g® u, or q = p(Bv (u, v are arbitrary terms). 
Using the derived rule DR3: 

If the formida contains the arbitrary term r, then this term could be replaced 
by any “ equivalent ” term s (the equivalence means that, for the valuation func- 
tion v, v £ r iff v € s), one could use instead of the terms q <g> u and p ® v 
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the “equivalent” terms. For example, instead of q ® u one could take q <8) it**, or 
( q * ® it*)*. In all such cases we also take it that p O q. According to the axioms 
of S 3dp , if 

(*) ® p v E r m at (o m ) for each m (1 < m < i9) and for some r?, £, (0 < 

i—r] 

£, r] < v\ £ > if), and if 

(**) ® p v C n at (oj) for each l (i? + 1 < l < d + p) and for some rj, £, or 

i=rj 

0 

(g) ps Qri for each l and for some 5, 9 , (v + 1 < 9, S < v + w; 9 > 5), then 

i=S 

h Opi A ... A O p v A P Pv+1 A ... A Pp v+W Or m and 

h Op! A ... A O p v A Pp„+i A ... A P p v+w —> P i'i for each l, m, which is not 
the case. Therefore, either condition (*), or condition (**) must not be fulfilled. 
On the other hand, by assumption, 

u t (Opi A ... A Op v A Pp„+i A ... A Ppv+w ) C v t (Or! A ... A A Pr^ + i A ... A 
Pr,? + p), it follows that 

(1) u t (Op 1 A...AOp.„APp„ + iA...APp t , +J „) C v t {Or m ) for each m (1 < m < i?) 

and 

(2) v t (Opi A ... A Op v A Pp„+i A ... A Pp„ + ,„) C v t (P ri) for each l (i? + 1 < 
l <19 + p). 

Consider expression (1). From definitions of valuation v it follows that 
i’t(Opi) A ... A v t (Op v ) A v t (Pp v+ i) A ... A v t (Pp v+w ) C v t (0 r m ), so 
(0) ifv 0 {Pi) and... and v a (p v ) and (v 0 (p v+1 ) orVi(p v+l )) and.. .and (v 0 {p v+w ) 
or Vi(p v+W )), then v 0 (r m ). 

Comparing the last expression to the correspondent definitions of v, one could 
see that to satisfy (<C>), the condition (*) must be fulfilled. Similarly, condition 
(2) gives the expression 

(00) if v 0 (Pi) and.. .and v 0 {p v ) and (v Q (p v+1 ) or Vi(p v+1 )) and... 
and (v 0 (p v+w ) or Vi(p v+W )), then v 0 {r m ) orVi(r m ). 

In accordance with definitions of v , to satisfy (00) , the condition (**) must 
be fulfilled. Therefore, both conditions (*) and (**) hold, and we get contradic- 
tion. 

Now consider the case 2. In which case it could be that, for some i (1 < 
i < n ), there is no j (1 < j < m), such that u t (d^) C v t {d J B ), but, at the same 
time, v t (d l A ) C v t {d l B V d 2 B V ... V d B ). By construction of DNF, there are the 
following possibilities. 

Case 2.1. Among the disjuncts d B , d B , ..., d B there are disjuncts d and -> d, 
which are both different from d\. But that situation is impossible, since, in that 
case, 

b d\ —> d x B V d B V ... V d B for any i (1 < i < n), which contradicts the 
assumption. 

Case 2.2. Among the disjuncts d Bl d 2 B , ..., there are disjuncts of the form 
d l A A / and d A A ~>f (conjunction d l A is a subset of the conjunction d A ). Suppose, 
we have the expression (•) H d l A — > d B V d 2 B V ... V d A A / V d\ A ~<f V ... V d B . 
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By the rule (DR2), from (•) we get H d l A — » d A A / V d l A A ~>f. Then, by the 
derived rule (DR3): 

If A — » B A(CV D), then A — >• (BAC)V(BAD) (which, in turn, is obtained 
from GA7 and GR3), H d A — > d A A (/V->/). According to GR2, either H d A — > 
d A , or H d A — > f V ->/. Since h d l A — » / V ~>f (GA12), then H -> which 
contradicts to the axiom (GA3).D 

One of the main points to notice about the considered system S 3 d p is that 
although S 3 dp avoids deontic explosion, it does contain a principle that if there 
are deontic dilemmas, cases where Op and Op* are both true, then there are 
true contradictions, cases where Op and ~^Op are both true. That is to say, Op A 
Op* OpA^Op is valid in the semantics SP 3 D, and is provable in S 3dp (with 
axioms S 3 d p A7, S 3 d p A8 and the rule S 3 d p Rl). That S 3 d p can accept deontic 
dilemmas, and hence real contradictions, and still avoid deontic explosion, is due 
to its being based on a paraconsistent logic, G, that rejects simple explosion, that 
a contradiction implies everything. However, by using quasi-matrix approach it 
seems possible to build deontic system in which both formulas Op A Op* — > 
Op A —<Op and Op A Op* — > Oq are no longer theorems. 

6 Deontic Dilemmas without Real Contradictions 

One of the possibilities to avoid both above mentioned formulas is to consider on 
the level of formulas of S 3 d the two valued quasi-matrix logic instead of classical 
two valued logic. Let’s reason as follows. If the act p is obligatory (possesses the 
value o), then this obligation (formula Op) is true. The obligation of the forbid- 
den act p is false, thus Op takes f. If the act p is normatively indifferent, then 
Op takes t/f. The cases where the obligation of the indifferent act is false are 
obvious. Now consider what is the possible source for the conflict of obligation 
Op A Op *? Normally, the code of norms is made so that it does not include 
inconsistent norms. The situation with inconsistent norms may arise when some 
act earlier considered as indifferent in relation to some code of norms, becomes 
obligatory or forbidden by that code. Suppose the two legislative bodies inde- 
pendently from each other make obligatory (forbidden) both indifferent acts p 
and p* . Obviously, such situation is contingent, but it can take place, thus we 
choose t as an alternative truth value for Op when the act p is indifferent. 

Consider the following semantics QM 3d . 

Language 

The language L 3dq is the same as the language L 3d . 

Formation Rules 

1. Terms, formulas and connectives for the acts are defined the same way as in 

s 3d . 

2. Definitions of the operators O, P: 

p Op P p 

0 t t 

1 t/f t 
b f f 
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The formulas take values from the field {t, /}. Definitions of logical connec- 
tives are usual. 

Formula A is valid in the given interpretation iff it takes the value t in each 
alternative interpretation caused by this interpretation; A is satisftable in the 
given interpretation iff it takes t in some alternative interpretation caused by the 
given interpretation; A is satisfiable in semantics QM 3d(? iff it is valid in some 
interpretation; A is valid in semantics QM 3d(? iff it is valid in each interpretation. 
The result of the formalization of the described semantics is the system S 3 dq . 



The System S 3dq 

(S3d g 2l0) All tautologies of classical propositional logic, 
(S 3dq Al) Op = Op**-, 

(S 3dq A2) Pp = Pp**; 

( S 3 dq A3 ) 0(p®q) = 0(p* ®q*)*; 

(S 3dq A4) 0(p®q)=0(p*®q*y-, 

(S 3dq A5) P(p® q ) = P(p*® q *)*; 

(S 3d? A6) P(p® q) = P(p* ® q*)*', 

( S 3 dq A7 ) OpDPp; 

(S 3d? A8) -P p D Op*-, 

( S 3 dq AQ ) 0(p®q)DOp/\Oq; 

(S 3d(? A10) P(p® q) D Pp A Pq-, 

( S 3d 9 ^ 1;L ) °P v ° c l D °(P ® 

( S 3dg^ 12 ) PpV Pq D P(p (B q); 



Inference Rules 

(S 3 d q Rl) Modus ponens for the formulas; 

(S 3 d <J f?2) Substitution rule for the terms and for the formulas. 

d e f 

Rem. Operator F (it is forbidden that) can be defined as F p = Op*. 

Theorem 1.6. The system S 3 d g is sound and complete with respect to semantics 

QM 3d(r 

Sketch of the proof: 

Soundness can be easily shown using the above table definitions. For the com- 
pleteness proof one has to prove the two lemmas. 

Lemma 1 is the same as the one for S 3 d. 

Lemma 2. There is a function | • | t such that it possesses all the properties 
of an interpretation function, and for each formula A, \A\t = t <£> A £ T . 
Consider the function | • \ T possessing the following properties: 

• \p\t = o <£> Op £ T; 

• \p\t = i & Pp A Pp* £ T ; 

• \p\t = b <=> Op* £ T; 

• \A\t = t A gT (A is a formula). 
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It can be shown that the function | • |t possesses all the properties of an 
interpretation function for logic S3 dq- Let’s show for example \p\x = o iff \p*\t = 
b. Suppose, \p\t = o, then according to definition of | • |, Op £ T. By S3d 9 Al, 
Op** £ T, and by definition of | • |, \p*\t = b. Now suppose that \p*\t = b, 
then Op** £ T, by S3d 9 Al, Op £ T, and \p\r = o. Another example. Let’s show 
that if \p\t = \q\r = i, then |p® q \t = i/o. Suppose, \p\r = \q\r = i, therefore, 
Pp A Pp* £ T and P q A Pg* £ T. Now suppose that |p ® q\r = b, then, by 
definition of | • | t, O (pffig)* £ T, then, by S3d q Al, S3d g A4 and S 3£ ; 9 A 9 , Op* £ T 
and O q* £ T. By lemma 1 , Pp* A Pp** T and Pg* A Pg** T, therefore, 
Pp A Pp* ^ T and Pgr A P q* £T, a contradiction, hence |p ® q\r = i/o. 

The final steps of the completeness proof are the same as the ones for the 
system S 3d .n 

One can easily see that both formulas Op A Op* D OpA~>Op and OpAOp* D 
Oq are not valid in semantics QM 3d? , thus the considered system S 3 d q accepts 
deontic dilemmas without classical contradictions. 

7 Conclusions and Further Research 

We have constructed the three different deontic systems, S3 d, S3 dp and S 3 dq, 
on the basis of possible world -free quasi-matrix semantics. The system 83^ 
contains the axioms SDLA2 and SDLA3 of SDL but does not contain SDLA1 
and the rule (SDLi?2) ^ (for example, \fs 3d 0 (pffip*)). But deontic explosion 
Op A Op* D Oq is still the theorem of S3 d- One of the purposes throughout our 
paper has been to build deontic system that allows for conflicts of obligation. 
The systems S3 dp and S 3 dq both satisfy that task but for the different reasons. 
The system S 3 d p represents modal extension of paraconsistent logic G, thus that 
S 3c [p can accept deontic dilemmas, is due to its being based on a paraconsistent 
logic. In case of S3 dq, the two valued quasi-matrix logic which acts on the level of 
formulas is not paraconsistent. The system S3 dq allows for conflicts of obligation 
but does not accept classical contradictions. 

The considered logic S 3( j can also be extended onto the case of five valued 
logic (Kouznetsov, [ 13 ]). Sometimes it is useful or even important to qualify the 
agent’s acts not only in terms of the strict norms - what an agent is obliged or 
what is permissible for her - but also in terms of weak norms - what is desirable or 
is undesirable from the point of view of some code. The system can be built 
as an extension of 83^ on the case where the action sentences take the values 
from the field { obligatory , desirable, indifferent, undesirable, forbidden}. The 
language L 5( i of S, 5( j differs from L ^ in the definitions of deontic connectives and 
in the definition of the operators- the two more operators are added, D (it is 
desirable that..., or it is weakly obligatory that...) and U (it is undesirable that..., 
or it is weakly prohibited that...). Obviously, the systems S5 dp and S 5^ can be 
built in a similar way as the correspondent systems S3 dp and S3 d q ■ 

As we mentioned, quasi-matrix approach seems to have advantages over pos- 
sible world semantics in that it allows to construct a wide range of modal logics 
including the ones weaker then the standard Kripkean systems. We expect in 
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further research to build quasi-matrix deontic systems which use on the level of 
formulas the four valued quasi-matrix logic. The formulas will take the values 
from the field {necessary truth , contingent truth, contingent false, necessary 
false}. By varying the definitions of implication and of deontic operators in four 
valued logic one can obtain various deontic systems depending on the consider- 
ations that are taken into account in the given semantics. 
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Abstract. In an organizational context the norms that apply to an 
agent depend on the roles he holds in the organization. The deontic 
characterization of structural roles is defined when the organization is 
created. But an organization is not a static entity. Among the dynamic 
phenomena that occur in an organization there are interactions between 
agents consisting in a transference of obligations or permissions from an 
agent to another. These kind of interactions are called delegation. In 
this paper we analyze different ways in which delegation occurs in an 
organizational context. We argue that the concept of “agent in a role” is 
relevant to understand delegation. A deontic and action modal logic is 
used to specify this concept. 



1 Introduction 

In an organizational context, agents’ behavior are ruled through norms defined 
by the organization. By norms we mean obligations, permissions, prohibitions 
or other deontic attributes. The norms that apply to an agent depend on the 
roles he holds in the organization. The deontic characterization of a role of the 
structure of an organization (structural role) is defined when the organization is 
created and is part of its identity. But an organization is not a static entity: it 
interacts with the external world (e.g. establishing contracts with other agents) 
and the agents that hold roles in its structure interact with each other. Among 
the dynamic phenomena that occur in an organization there are interactions 
between agents consisting in a transference of obligations, permissions, respon- 
sibilities, powers or other normative attributes, from an agent to another, or to 
be precise, from an agent in a role to other agents in roles. These transferences 
may be temporary or permanent, and correspond to a sort of redistribution of 
competences, temporary in many cases, that may change the organization way 
of working but do not change its identity. 

These kind of interactions are usually called delegation. Delegation is a com- 
plex concept, having multiple interpretations depending on the context where 
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it is used. Several authors have addressed this issue, like [5], [12], [13], [4], [18], 
among others. 

With this paper we want to contribute to the understanding of this concept, 
analyzing different ways in which delegation occurs. We focus the study in a role- 
based organizational context, taking organizations as normative systems (set of 
interacting agents whose behavior is ruled by norms) . A role-based organization 
has a stable structure consisting of a set of roles, whose deontic characterization 
is described by a set of obligations, permissions or prohibitions. Within this 
context, agents always act in some role. 

A delegation relationship may be established between agents holding roles of 
the organization structure or between agents inside the organization and agents 
outside of the organization. 

We do not analyze motivations of agents to enter in a delegation relationship, 
nor the success or failure of delegation. We do not consider, either, informal or 
implicit delegation. We are interested in explicit and formal delegation relation- 
ships, where the agents involved are aware of the relationship, as well as all the 
agents that interact with them. 

In this paper we will show how the delegation concept can be clarified in a 
role-based organization, using a deontic and action logic to express its different 
meanings. 

The rest of the paper is organized as follows: we briefly summarize the deontic 
and action logic we will use to formally express the concepts analyzed. Next we 
present the formal model we adopt for organizations, based on this logic. Then 
we discuss the concept of delegation and how it could be expressed in the formal 
model proposed. We conclude with the discussion of further logical principles in 
order to deal with delegation in a role-based organization. 



2 Action and Deontic Logic 

Following the tradition initiated by Kanger ([9], [10]), Porn ([15], [16]) and Lin- 
dahl [11], and followed by many others, of combining deontic and action logics to 
describe social interaction and complex normative concepts, a logical framework 
has been proposed by Pacheco and Carmo ([2], [14]) that tries to capture the 
notion of action of an agent playing a role. To know the role an agent is playing 
when he acts is crucial to analyze the deontic classification of the action (e.g. is it 
a permitted action?) and the effects of the action (e.g on action of other agents, 
or legal effects - obligations resultant from the action). It was proposed a new 
action operator of the form E a:r (for a an agent and r a role), being expressions 
of the form E a:r if read as agent a, playing the role r, brings it about that if. 
These actions operators were combined with personal deontic operators in order 
to express obligations and permissions of agents in roles (O a;r ^ - read as agent 
a is obliged to bring about if by acting in role r ; Pa-.r’f’ ~ read as agent a is 
permitted to bring about if when acting in role r). In [2] and [14] it is discussed 
if these operators should be primitive or derived from impersonal deontic opera- 
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tors and action operators (e.g. O a - r if) = OE a:r ip). Here we omit that discussion 
and adopt O a:r and P a:r as primitives, and define F a:r as -iP a;r . 

This logic has been used as the formal support to the specification and analy- 
sis of role-based organizations. In this paper we will use it to discuss the concept 
of delegation in the same organizational context. 

Next, we will present the main features of the logic proposed in [2] and [14], 
in a simplified way and omitting reference to the underlying semantics. 

2.1 The Logic Cda'- Formal Language 

Cda is a modal (deontic and action) first-order many-sorted language. The non- 
modal component of C-da is used to express factual descriptions, and properties 
and relationships between agents. It contains a finite number of sorts, not related 
with agents or roles, and three special sorts: Ag (the agent sort), R (the role 
sort) and AgR (the agent in a role sort). 

As usual, for each of these sorts we assume an infinite number of variables, 
and possibly some constants. (We are not considering for the moment variables 
of the sort AgR). There may be functions between these sorts, but we do not 
consider any function with Ag as co-domain (the terms of sort Ag are either 
variables or constants.). The terms of each of these sorts are defined as usual. 

Cda also contains a finite number of role generators, generically denoted by 
r< 7 ,of sort (— > R). There is always a role generator, denoted by itself. Moreover, 
for each role generator rg, there exists a predicate ( qualification predicate), 
denoted by is-rg of sort (Ag) and denotes a property that an agent may have. 

The terms of the sorts R and AgR are built as follows: 

(i) If rg is of sort (— > R), then rg() is a term of sort R (we will write rg, 
instead of rgQ); 

(ii) If £ is a term of sort Ag and r is a term of sort R, then t : r is a term of 
sort AgR. 

From now on, we use r, n,..., to generically refer to roles, and a,a±,..., to 
generically refer to a term of sort Ag (either a constant and a variable), and 
we will continue using t,t\,. . ., to generically refer to terms of the appropriate 
sorts. Finally, a : a is used as an abbreviation of a:itself and qual(a : rg) is an 
abbreviation of is-rg(a), and intuitively means that agent a is qualified to play 
the role rg. 

The formulas of Cda are inductively defined as follows: 

(i) if p is a predicate symbol of sort (si, . . . , s n ) and t\, ... ,t n are terms of 
sort s i, • . • , s n , then p(t \, . . . , t n ) is an atomic formula; 

(ii) if B is a formula, then is a formula; 

(iii) if B\ and B 2 are formulas, then (B\ A B 2 ) is a formula; 

(iv) if B is a formula and X s is a variable of sort s, then (\/ x s)B is a formula; 

(v) if B is a formula and a : r is a term of sort AgR, then E a:r B, O a - r B and 
P a -.rB are formulas. 
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The other standard logical connectives (V, —y and 00 ) and the existential 
quantifiers are introduced through the usual abbreviation rules, and parentheses 
may be omitted assuming the following priorities: first A; then V; and finally -A 
and f-h The forbidding operator is defined as follows: F a - r B a = ->P a . r B 



2.2 Axiomatization of Cda 

The logical principles satisfied by the proposed operators have been discussed 
and presented in [2] and [14]. Here we just list some of those principles. 

Naturally, we assume that all tautologies are axioms of our logic, and that 
we have the rule of Modus Ponens (in the sense that the set of theorems of our 
logic is closed under Modus Ponens). 

With respect to the first-order component, we have the general properties of 
quantifiers. We have the generalization rule (if b B then b (\/ x )B), and the 
following axioms (schema): 

(V*)(Bi -> W) -o ((V X )B i -o <Sx)B 2 ) 

B —y (\/ x )B, if x does not occur free in B 

(Vrc)-B — > B[xfree/t\, for t a constant of sort s or a variable xi 
such that x does not occur free in B within the scope of (V X1 ). 



(B[x s free/t] denotes the formula we obtain when we replace (in B) the free 
occurrences of X s by t.) 

The formal properties of the action operator E a:r are described bellow: 

Axioms: 

(Be) E a -. r B — y B 

(Ce) Ea-.rA A E a:r B > E a:r (A A B) 

(Qual) Ea-.rB —y qual(a : r) 

(Itself) (V x )qual( x : itself ) 

Proof rule: 

(REe) If h do H then h E a -.rA -40 E a:r B 

With respect to the formal properties of the cleontic operators, and of the re- 
lationships between each other and with the action operator, we consider the 
following axioms and proof-rules: 



Axioms: 

(Co) Oa:rA A O a :rB — > O a :r(A A B) 

(O — > P) Oa-.rB — y Pa-.rB 

(O —y ~<P^) O a -.rB —y ^P a:r -^B 

(O A P) Oa-.rA A Pa-.rB — > Pa:r(A A B) 

Proof rules: 

(REo) If A -yy B then b O a -. r A -o- O a:r B 

(RMp) if b A — y B then bP n:r d->P aT 6 

(RMep) If b E ai;ri A — y E a2:r2 B then bP ai;ri doP 02;r2 



B 



More details can be found in the above referred papers. 
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3 Formal Specification of Role-Based Organizations 

3.1 Organizations as Institutional Agents 

Organizations are legally classified as artificial persons. Artificial persons are col- 
lective entities that have a real existence in human societies: they have juridical 
personality, which means that may be the subject of obligations or rights and 
they also have legal qualification, which means that they can exercise their rights 
and be responsible for the unfulfillment of their obligations. Based on this legal 
concept of artificial person, we introduced in [14] the concept of institutional 
agent to model organizations. 

Institutional agents are agents. They interact in the society like any other 
agent: they can establish contracts or other normative relationships with other 
agents, they can hold roles, they may be the subject of obligations or other 
normative attributes, and may be responsible for the nonfulfilment of obligations 
or other “non ideal” situations. 

An institutional agent has a structure formed by a set of roles. Each structural 
role is cleontically characterized by a set of obligations, permissions, or other 
normative attributes. This abstract structure is supported by other agents: the 
holders of the roles. When an agent act in a role, his behavior will be evaluated 
according to the deontic characterization of the role he is playing. 

An institutional agent is not capable of direct action. It always act through 
the holders of the roles of its structure. There must be defined how obligations of 
an institutional agent are transmitted to the roles of its structure (and indirectly 
to the holders of those roles), stating who is responsible for fulfilling them. It 
must be also defined what are the representative roles of the institutionalized 
agent, stating who is authorized to act on behalf of the institutional agent. 

An agent may hold several roles. 



3.2 Some Extensions to the Logic 

Next we extend the logic in order to obtain a framework with the adequate 
expressive power to specify organizations as institutional agents. 



Deontic characterization of roles and agents in roles. The deontic char- 
acterization of a role in an organization is part of the identity of the organization 
and does not depend on the agent that hold that role in a particular moment. 
To capture this idea, deontic notions are attached to roles, but they are actually 
interpreted as applied to the holders of such roles, when acting in such roles 
(deontic notions are only meaningful when applied to agents). Thus, we do not 
introduce new operators, but just new abbreviations: 

O r B °= ( V x )(qual(x : r) -S- O x , r B) 

P r B °= ( M x ){qual{x : r) -»• P x:r B) 

F r B °= (' M x ){qual{x : r) -> F x:r B) 
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Apart from the set of obligations, permissions and prohibitions that are in- 
trinsic to the role and characterize the identity of the organization, other obliga- 
tions or permissions may be attributed to the role dynamically, resultant from 
the interaction of the organization with the external world. For instance, when 
an organization i has an obligation ip resultant from a contract established with 
other agent, that obligation will have to be transmitted to specific roles of the 
organization’s structure, stating who is responsible for its fulfillment (on behalf 
of the organization): Oi : iip — > O r ip (for r a structural role). 

By knowing the qualifications of an agent, that is, the roles the agent holds, 
we know what are the obligations, the permissions and the prohibitions that 
apply to him. But there are situations where the cleontic characterization of an 
agent may be more complex. 

A first case, happens when an agent establishes a contract with an organi- 
zation accepting to hold a particular role of its structure. In most cases (e.g. 
collective labor contract) the agent, by accepting to hold a role, just inherits 
the deontic characterization of the role. But, in other cases, other obligations or 
permissions may be attributed to the agent in that role, distinct from the ones of 
the deontic characterization of the role. For example, an administrator may ne- 
gotiate with a company to have his personal phone bills payed by the company; 
or an employee of a foreign company that has to work abroad, may negotiate 
with the company to have some compensation (e.g. take his family with him, 
pay for children school). These obligations will be called personal obligations in 
a role, represented by O a:r ?/> (where a is an agent and r is a role) and are not 
intrinsic to the role. 



Representative roles. Some roles may be classified as representative roles of 
other agents. This means that the holders of those roles may act on behalf of the 
represented agents within the scope of representation defined for those roles. 

In order to represent this, the following notation has been introduced in [14]: 

r:REP(a, B), that is read as follows: “r is a representative role of a with scope of 
representation B”. The expression r:REP(a, B) can be seen as an abbreviation 
of: 

(y x )(E x:r B E a , a B). 

Here we extend this notation allowing the represented agent to be in a role 
other them the role itself. So we have: 

rl : REP (a : r2, B) = f (V x )(E x:rl B -4 E a:r2 B). 

We can now add two properties imposing that B should be in the scope of 
r2 and in the scope of rl: 

rl : REP(a : r2, B) — > P r2 B 

rl : REP{a : r2, B) — > P r \B 

When an agent acts as representative of another agent he does not act on his 
own behalf. So, it is natural to impose that: 
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E x:r \B A r 1 : REP(a : r2,B) — > ->E x:x B 1 

There might exist cases where we can consider that a role rl is a repre- 
sentative role of an agent a in a role r 2, for everything permitted in rl. Using 
rl : REP{a : r2,*) to denote that, we can capture such situation by imposing 
the following axiom: rl : REP(a : r2, *) A P r \B — > rl : REP(a : r2, B) 

Representative roles are crucial for organizations because an organization 
cannot act directly - it needs other agents to act on his behalf. Those agents are 
the titular of the representative roles. 

Representative roles are not necessarily roles of the structure of an institu- 
tionalized agent. They may result from contracts or other normative relations 
that agents are free to establish between each other. An institutionalized agent, 
for instance, may also establish arbitrary representation contracts with other 
agents attributing to them representative roles for specific situations. Contracts 
are discussed below. 

3.3 Contracts 

Agents in a society are free to establish arbitrary normative relationships be- 
tween each other. A particular kind of those relationships are contracts. 

When two agents 2 establish a contract between each other, they attribute 
obligations, permissions and prohibitions to each other. They may also attribute 
roles (contractual roles) to each other and deontically characterize those roles 
(that means, they define what are the obligations, permissions or prohibitions 
associated to each role). Some of the roles may be classified as representative 
roles of one of the agents. In that case, it must be also defined in the contract, 
the scope of representation for that role. 

Frequently, contracts also include conditional obligations (or conditional per- 
missions). In particular, in legal contracts it is usual to include conditional obli- 
gations describing the effects of the fulfillment or violation(unfulfillment) of other 
obligations in the contract. For instance, besides an obligation O x:ri A on x a 
contract C(x,y) may include an obligation on y on the condition that x fulfills 
the previous obligation 

^x:r^A > Oy :r2 B , 

or another obligation on x if he does not fulfill it 

'Rx:rg\A ^ O x:r g 1 B . 

Using Ci( x, y) to denote (the content of) a contract between agents x and y, 
we may now represent some examples. 

A first example is a contract where agents attribute roles to each other, 
define in the contract the deontic characterization of the two roles, classify one 
of the roles as a representative role of the other agent and define a conditional 
obligation on one of the agents: 

1 This does not mean that the representative agent is not responsible for “bad behav- 
ior”. 

2 For simplicity reasons we only consider contracts between two agents. 
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Cl(a,b) = qual(a:rl) A qual(b:r2) A O a:r iA A Pa-.riB A 

Ob:r2C A Ea.rlB — > Ob:r2D A rl REP(b, A) 

A second example is a titularity contract, where agent a accepts to hold 
role r in the organization i. The deontic characterization of the role r is not 
defined in this contract. It is defined in the organization and is inherited by 
agent a because he will become holder of r. However, the contract also assigns 
additional personal obligations and permissions to agent a in role r: 

i) — qual(a:r) A O a - r B A P a:r C A Oi:itseifB 

A E a:r ^B — > Og- r F 

Finally, an example of a contract established by two agents a and b , where 
no roles are attributed to each other. So, the obligations and permissions are 
assigned to each agent in the role of itself: 

(H3(ct, 6) — OaiitselfA A Ob:itself B 

R(Ba:itself—'A >■ Oa:itself t/)A ( Eb:itself— f B > Ob-.itselfG ) 



3.4 Specification of Organizations and Societies of Agents 

A formal model for organizations based on the concepts we have formalized 
above, can now be presented. 

The specification of an organization involves a name, i, and a structure: 
STi =< Ri, DCRi,TOi, RERi >, formed by: 

Ri : a set of roles - structural roles of the organization. It is constituted by a 
finite set of atomic formulas of the form is-role-str(r, i), stating that the 
role r is a role of the structure of the organization i. 

DCRi : the deontic characterization of each role - obligations, permissions or 
prohibitions that are intrinsic to the role. It is a (finite) set of formulas of 
the form O r A , P r A or F r A, where r is a structural role of the organization 
i. 

TOi : transmission of obligations from the organization to specific roles of its 

structure. It is formed by a set of formulas of the form Oi : i tse ifA — > O r A 
(for r a role of the structure of i). 

RERi : contains information about the representative roles of the organiza- 
tion and its respective scope of representation. It is constituted by a set of 
formulas of the form r : REP(i : i,B). 

The specification of an organization i may also include other components, not 
considered here. 

The description of < i, SR > contains those aspects that do not change and 
define the identity of the organization. We need also to include in the specification 
of i, information describing the agents that in the present moment hold the roles 
r of the structure of i. Since this component corresponds to relationships between 
i and other agents (contracts that i establishes with each agent), we have decided 
to include it in component NR (normative relationships) of the specification of 
the society of agents (see below). 
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A society of agents, SA, is: SA =< I A, nIA , NR, GK > where: 

I A : Specification of each institutionalized agent (organization) of the society. 

So it is formed by a set of pairs < x, ST X >, as explained above. 
nIA : The component nIA contains the identification of the other agents that 
exist in the society. 

NR : Contains normative relationships that agents have established between 
each other, and in particular the contracts that are actually in force. Con- 
tracts between organizations and agents, attributing to the agents titularity 
of roles of its structure, are also included in this component. 

GK : Contains general knowledge about the society. 

For more details and an example see [14]. 

4 Delegation 

The concept of delegation appears in many different contexts having distinct 
interpretations. Next we discuss some possible interpretations of it, and try to 
express them in a precise way using the action and deontic logic presented above. 
This formalization process may contribute to clarify the concept of delegation. 

4.1 What Do We Mean by Delegation? 

We can classify as delegation a set of different situations, all having in com- 
mon some kind of transference of tasks, responsibilities, permissions, obligations, 
powers or other normative attributes, from one agent to another. The different 
interpretations of the concept depend on issues like: why agents delegate, how 
do they delegate, what is delegated, among others. 

An agent may want to delegate e.g. an obligation to other agent because he 
is not capable of fulfilling it (e.g. he does not have resources nor knowledge), he 
has not practical possibility of fulfilling it (e.g. he cannot be in two places at the 
same time), or any other reason. 

In this paper we will not analyze why an agent delegates or why an agent 
accepts a delegated task, obligation, or other normative attribute. It is outside 
the scope of this paper to express and reason about motivations or intentions of 
agents involved in a delegation relationship. We also assume, without represent- 
ing it explicitly, that when an agent delegates an obligation to another agent, he 
also transfers to that agent all the resources required to the effective fulfillment 
of the obligation. 

Lets discuss now what may be delegated and how this delegation may occur. 

Delegation as a normative relationship. First of all, we consider that dele- 
gation is a normative relationship between agents, or to be more precise, between 
agents playing roles. By this we mean that, agents do not simply delegate tasks, 
but delegate obligations, permissions, prohibitions, responsibilities, powers, ... to 
do tasks. For instance, if we simply say that the director of the Informatics De- 
partment delegates the task of writing the annual report to his secretary , what we 
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usually mean is that she has the obligation of writing the annual report on behalf 
of the director. But that information is not explicit in the initial statement. 

Another example: if we say that a company X delegates in a specific admin- 
istrator the task of selling a property, do we mean that that administrator has 
permission to sell the property, or that he is obliged to sell it, or ...? The intended 
meaning is not clear. 

On the other hand, if we say that a company X delegates in a specific ad- 
ministrator the obligation to sell a property, the meaning is clearer. Considering 
agents in roles instead of only agents is important, because as we will see, char- 
acterization of delegation depends on the roles agents are playing 3 . 

For simplicity reasons, we use only the cleontic concepts of obligation and 
permission, in the description of the content of a delegation act 4 . In a deeper 
analysis other concepts like the one of power should be included. The normative 
concept of responsibility is only informally and indirectly referred. 

Thus, we want to express statements similar to: 

agent x delegates on agent y the obligation to bring about <p and the permission 
to bring about ip. 

What do we mean by this statement is not clear, yet. 

A first remark that should be made, is that the agents involved in this del- 
egation process, are part of some organization or some society. So, according to 
the perspective we adopt in this paper, they are playing roles (at least the role 
of itself). So we should reformulate the above statement: 

agent x, playing role rl, delegates on agent y, which is playing role r2, the 
obligation to bring about (p and the permission to bring about ip. 

This new statement poses some other questions: 

— Is agent x (when acting in role rl), permitted to delegate the obligation to 

bring about <p and the permission to bring about ip? 

— Is agent y (when acting in role r2), permitted to accept the delegated obliga- 
tion to bring about (p and permission to bring about ip? 

The answer to these questions depends on the deontic characterization of the 
roles played by the agents. 

3 We can be more precise and say that in some situations what is delegated are obli- 
gations (permissions, powers, ...) to do some actions and in other situations what 
is delegated are obligations (permissions, powers...) to bring about certain states of 
affair, without specifying the concrete actions that should be made to achieve that 
state of affairs. It is a question of abstraction, that we do not address in this paper. 
Here, we adopt the latter version, omitting details about concrete actions. For works 
that use and discuss this distinction, see, for example, [1], [12], [13], [8]. 

4 Moreover, it seems strange to us that agents could delegate prohibitions: they del- 
egate obligations and/or permissions to bring about a state of affairs, and not to 
avoid a certain state of affairs. Formulas like Fi, r A seen as O^Ei, r A, in our opinion, 
should not be delegated. However, formulas like OEi :r -<A would be acceptable. But 
this issue needs further research. 
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It seams reasonable to require that the obligation (p and the permission ip 
referred, should be in the scope of role rl (i.e. it should be possible to infer them 
from the deontic characterization of role rl). According to this interpretation, 
we can only delegate obligations and permissions attributed to us 5 . Here, we 
only consider delegation cases that verify this restriction. 

We also assume that an agent cannot delegate the obligations and permissions 
he has in a role that are not intrinsic to the role (that are not in the deontic 
characterization of the role), but result from the interaction of the agent with 
the organization, such as personal obligations or permissions negotiated in the 
labor contract, or obligations that result from sanctions to his behavior. 

When an agent accepts a delegated obligation (permission,...), this new obli- 
gation will be “added” to the deontic characterization that applies to him re- 
sultant from the roles he holds. Therefore, his actions will be evaluated in this 
new deontic context. But, in the model we adopt, obligations and permissions 
are assigned to agents in roles. Thus, a question arises: 

Are the obligations and permissions delegated to an agent attributed to 
that agent in the role he is playing in an organization? 

In most cases yes, but in some other cases no. 

In the former cases, the delegated obligations and permissions are just added 
to the agent in the role deontic characterization. For example, when the direc- 
tor of Department of Informatics delegates on his secretary the obligation to 
produce the annual report, this new obligation will be added to the deontic char- 
acterization of the person playing the secretary role ( O x:sec <p ). This new deontic 
attributes are not intrinsic to the secretary role, they are resultant from the 
interaction between the holder of secretary role and the holder of director of 
Department of Informatics. In this context, it seems natural to impose that the 
delegated obligation or permission should not enter in conflict with the deon- 
tic characterization of the role played by the agent that accepts them. By not 
entering in conflict we mean, in this context, that the same agent should not 
be under the obligation or permission to bring about A because he holds a role 
and, at the same time, under the obligation or permission to bring about ->A, 
because he accepts a delegated obligation or permission. For later reference, we 
will call this kind of delegation composed delegation. 

There are, however, other situations where what is delegated is a set of obli- 
gations and permissions that should not be seen as an additional characterization 
of the role played by the agent who accepts them, because they have a distinct 
nature. In this cases, what is delegated may be seen as a set of obligations and 
permissions - a new role, as we will see below - that is attributed to the agent 

5 There are situations where an agent has permission to “delegate” on others obliga- 
tions (permissions,...) that are not attributed to him. For example, an administrator 
may “delegate” on an employee the obligation to perform a task that he is not 
obliged to perform. Although in natural language, the word “delegate” is sometimes 
used in similar contexts, we have doubts that this situation should be classified as a 
delegation case. So, we do not consider this kind of situations in this paper. 
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independently of other roles he is playing (although the role an agent is playing 
may be relevant to choose him as delegate). In this case, avoiding conflicts (of 
the kind mentioned above) is not relevant: agents may have conflicting obliga- 
tions when playing different roles. For instance, it is possible to have O x:r 2 A and 
O x: r 3 -'A. As an agent can act only in a role at a time 6 he will have to decide 
what obligation he will fulfill and what obligation he will violate ' . 

A typical example of this kind of delegation is when an agent in a role del- 
egates some of its obligations or permissions to another agent (that may even 
be from outside the organization) through a contract, attributing to him a spe- 
cific role. For later reference, we will call this kind of delegation independent 
delegation. 

Role-based Delegation. In the role-based organizational model proposed in 
the previous section, roles are characterized by a set of obligations, permissions 
and prohibitions. So, we can aggregate the delegated obligations and permissions 
in a role and say that agents delegate roles. This delegated role may be just 
an artifact (a way of aggregating obligations and permissions and naming it) 
or, on the contrary, may be a role of the organization structure (usually part 
of another role of the structure), or a new role defined in a contract. In this 
paper we assume that the roles of the structure of an organization are composed 
of smaller roles corresponding to functions or competences associated to the 
former role. Those smaller roles may be viewed as a way of structuring the set of 
obligations, permissions, ... that deontically characterize the role, into units that 
“make sense” . For example, a lecturer at some university, has obligations related 
with his competence of teaching, others related with research, other related with 
bureaucratic functions, ... We will assume, in this paper, that an holder of a role 
may only delegate one of its role units. The deontic characterization of each of the 
role units that constitute a role, is defined in the structure of the organization. 
So, we don’t need to deontically characterize the delegated role when two agents 
establish a delegation relationship. We shall return to this issue later. 

In order to represent this role-based delegation, we introduce the following 
notation Delegate^ x : rl,y : r2,r3), that is read as follows: “agent x playing 
role rl delegates the role r3 on agent y that is playing role r2” . Before we define 
the kind of formulas that correspond to the expression Delegate{x : rl,y : 
r2,r3), we need to discuss some additional features of the delegation concept. 

If we assume the properties discussed above for what is being delegated, we 
may say that an agent in a role may only delegate roles that are part of the role 

6 In cases where we can assume that agents may play several roles at the same time, 
we consider that there is some kind of composition of those roles, as discussed above. 

7 There are other kind of conflicts related, for instance, with incompatibility of goals 
(functions, competences,...) associated to roles. For instance, the President of BP 
cannot be President of GALP (BP and GALP are two known oil companies). We 
can express this kind of incompatibility using the relation <> proposed on [14], 
where r2 <> r3 is defined as (W x )(qual(x : r 2) — > -iqual(x : r 3)), stating that the 
same agent cannot hold the two roles. Although in this paper we do not consider 
this kind of incompatibilities to restrict delegation, we intend to do it in the future. 
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he is playing: Delegate(x : rl,y : r2,r3) — > r3 < r 1, where r3 < r 1 is read 

“r3 is part of role rl” (the predicate symbol < will be discussed later). 

In the context of composed delegation, the role r3 that is being transferred to 
agent y will now be “added” to the role r2 he was playing, in the sense that the 
deontic characterization of the two roles will be joined, as if there were a new 
role. To capture this idea we will use the function on roles, + : R x R — > R 
(to be discussed later). We can say, then, that delegation makes y hold role 
r2 + r3. This is in fact a new role of the organization and its inclusion in the 
structure depends on the permanent or transitory character of the delegation. 
So, in the definition of the delegation relationship the following role attribution 
must occur: 

def 

Delegate c (x : rl, y : r 2, r 3) = is — r 2 + r3(y) A . . . 

As we said before, in a context of independent delegation this role composition 
should not occur. The delegated role exists by itself and the agent to whom the 
role is delegated may act either in role r 2 or in role r3. In this case we must 
have: 

def 

Delegatei(x : rl,y : r 2,r3) = is — r3(y) A . . . 

Transfer of responsibility. Another issue that must be discussed is whether 
the obligations and permissions delegated to other agents, stay or not in the role 
played by the agent that delegates them. We will consider two situations: share 
of responsibilities and complete transfer of responsibilities. 

Share of responsibilities. In this case, the agent that delegates obligations and 
permissions, also keeps them. So he shares the responsibility with the agent to 
whom he delegated them. This delegation case corresponds to a representation 
relationship. This means that when an agents delegates a sub-role to another 
agent, he his assigning him a representative role. We can express this in our 
logic through the following formulas, for composed delegation and independent 
delegation, respectively: 

de f 

Delegate cs (x : rl, y : r2, r 3) = is — r 2 + r3(y) A r*3 : REP(x : rl, *) 
or 

de f 

Delegatei s {x : rl, y : r2, r3) = is — r3(y) A r3 : REP(x : rl, *) 

In this case the agent y will act on behalf of the agent x. 

Complete transfer of responsibilities. In this situation, when the agent delegates 
obligations or permissions he is no longer responsible for them. This means that 
those obligations and permissions are excluded from his role. The delegated role 
should be “subtracted” from the role held by the agent that delegates it. In this 
case, the role of the agent that delegates, is changed and becomes a sub-role of 
the initial role. 

A possibility to express these role changes, would be to introduce in the 
language another function on roles: — : Rx R — >• R (to be discussed later) and 
use it as follows: 

def 

Delegate c t(x : rl, y : r2, r3) = is — rl — r 3(x) A is — r2 + r3 (y) 
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or 

def 

Delegateu{x : rl,y : r2,r3) = is — rl — r3(x) A is — r3(y) 

But this possibility needs further research 8 . 

For simplicity reasons, in the rest of the paper we will use Delegate(x : rl, y : 
?’2, r 3) whenever it is not relevant to distinguish the particular kind of delegation 
used. 



Forms of delegating. There are several forms of delegation. We will consider 
some of them: delegation by command, through a joint action, by institutional 
context, or implicitly. 

Delegation by command. When agent x in role rl has some kind of authority 
over agent y in role r 2, delegation may be unilateral and have the form of a 
“command” , which can be expressed as follows: 

E x:r iDelegate(x : rl,y : r2,r3). 

Delegation by joint action. Other frequent form of delegation is through a joint 
action, where both x : rl and y : r2 decide do establish a delegation relationship. 
To express this joint action, we will use the action operator proposed in [14], 
E'{ai:ri,...,an:m}i indexed by a finite set of agents in roles. 

Thus, we extend our logical language Cda with this operator. The formulas 
of the extended language {C\, A ) are defined as follows: 

— If B is a formula of Cda , then B is (also) a formula of C^y, 

— If B is a formula of C-da and ti, . . . , t n (n > 2) are terms of sort AgR, then 

is a formula of Ci^ A (a joint action formula); 

— Boolean combinations (through -> and A) of formulas of C and universal 
quantifications of formulas of C^ A , are also formulas of C^ A . 

We consider that each joint action operator Ei ai:ri an :r„} is of type ETC, 

and the qualification axiom extends naturally to joint action formulas as follows: 

E{a 1 :r 1 ,....a n -.r n }B qual(a i : n) A . . . A qual(a n : r n ) 

We are now in position to express delegation established through a joint 
action: 

y . r 2 }Delegate(x : rl,y : r2,r3) 

Institutional delegation. The several delegation situations we have analyzed are 
just particular cases of contracts between agents. So, another claim could be that: 
to delegate is to establish a contract with the particularities we have discussed. 
But this is not accurate. There are cases where delegation does not correspond 
to a relationship between the agent that delegates and the agent that accepts 
the delegated role. 

8 Examples of open questions are: Should we cancel the qualification of x to play role 
rl ?, or What is the meaning of having r — r?. 
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Consider for instance a situation where an agent x that plays role rl in an 
organization is absent. It is usual that another agent 2 (e.g. his boss, that plays 
role r) delegates on other agent ( y that plays role r2) the role rl, until x returns 
to the organization. We can express this situation by 

E z:r Delegate(x : r\,y : r2,rl) 

Sometimes these situations are predefined in an organization, and agent z 
might be the institutional agent itself. 

Informal delegation. We do not consider implicit delegation, in the sense of infor- 
mal delegation relationships that agents may define between each other. Those 
relationships have no normative effects, in the sense that, if something fails, 
responsibilities could not be attributed to the agents involved. 

4.2 Examples 

So, we conclude this section presenting some examples of different types of del- 
egation. 

Example 1. One of the functions of the Director of Department of Informatics 
(ddi), a, is to produce an annual report, (wr). Associated to this sub-role (wr) 
there is the obligation to write the annual report of the Department (f>) and the 
permission to use the director's computer (<j>). He delegates on his Secretary (sdi), 
c, this role wr. 

Ea-.ddi Delegate cs (a : ddi,c : sdi,wr) a = 

Ea-.ddi is — sdi + wr(c) A wr : REP(a : ddi, *) 

The role delegated is called wr and is a part-of role ddi. Role wr is charac- 
terized as: P wr (f>A O wr if The secretary writes the report on behalf of the director 
(i.e. her action will count as an action of the Director). He is still responsible for 
the report. Notice that this delegation has the form of a command (due to the 
authority the Director has over the Secretary). 

Example 2. The Director of Department of Informatics (ddi), a, has the obli- 
gation to convoke the General Assembly of the Department (4>), once a year. He 
delegates this task, permanently, on the Assistant-Director (addi). 

E{a:ddi,b-.addi} Delegate ct (a : ddi, b : addi, cga) “= 

E{a-.ddi,b:addi} - addi + cga(b) Ms - ddi - cga(a) 

The role delegated is called cga and is part of role ddi and is characterized 
by O cga (j). This role is added to the role addi and subtracted from the role ddi. 
So, from now on, the agents a and b will hold different roles. 



Example 3. The Director of Department of Informatics (ddi), a, will be absent 
and delegates in the Assistant-Director (addi),b, all his competencies. 

E{a:ddi,b-.addi} Delegate cs (a : ddi, b : addi, ddi) °= 

E{a-.ddi,b:addi} is — ddi + addiib) A ddi : REP(a : ddi, *) 
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The role delegated to b is now the whole role ddi. In the absence of the 
Director of Department a, b will act as his representative , for everything the 
Director would have to do or would be permitted to do. 

Another possible interpretation of this situation would be to say that, during 
that period, b is the director of the Department of Informatics. The main dif- 
ference between this interpretation and the one presented before, is that in this 
case, b would be the only responsible for his actions as Director of Department. 
While in the previous case, the responsibility also goes to a. In this latter case 
we would have: 

E{a:ddi,b-.addi} Delegate (a : ddi , b : addi, ddi) °= 

E{a:ddi,b:addi} 2.S‘ ddi{b) 

5 Extensions to the Formal Specification 
of Role-Based Organizations 

In order to include the previous role-based delegation on the formal specification 
of organizations we need to consider further cleontic logical principles related 
with the concepts of part-of-role, joining roles and role subtraction mentioned 
before. 

With respect to the concept of part-of-role we introduce in the language a 
new predicate symbol < where rl < r2 expresses the fact that rl is part of role 
?’2, which means that all obligations and permissions that characterize rl also 
characterize r2. Thus the logical principles: 

rl < r2 — >■ ( O r i<j> —y O r 24 >) and 
rl < r2 — y P r i4> — 1 Pr 2 <t>- 

follow intuitively from what we want to express. 

The joining roles function + : R x R — y R also brings the need for the 
following logical principles: 

Or A — t Or+s-A 

O r+s A — y {O r A V O s A) 

P r A — y P r -\. S A 
Pr+sA -y {P r A V PsA) 

that follow the idea that a composite role also inherits all the obligations and 
permissions of its role composites. 

On the other hand, the subtracting role function — : Rx R — > R , introduces 
the need for the following logical principles: 

OsA — ^ 'Or — s A 

P a A — y —'Pr—sA 

following the idea that role obligations and permissions no longer apply when 
this role is subtracted from another role (the main role). Note however that the 
other obligations and permissions remain in the main role, i.e. 
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O r A A 'O s j 4 — y O , — S A 

O r —sA — y Or A 

Over and above the deontic principles we naturally assume role composition 
expressed by functions + and — as a way of expressing part-of-roles: 

r < r + s 
r — s < r 

Finally, 

E x:r A A is — r + s(x) — » E r+a A 

may help to characterize obligation fulfillment in this new deontic context. 

Concerning the specification of organizations, our main idea is to specify 
organizations by roles r fragmented into smaller roles rl, r 2, . . ., rn and express 
this by r = rl + r2 + . . . + rn. Intuitively, each part ri of role r may correspond 
to a particular function (or competence) associated to role r. We will assume 
that an holder of role r may only delegate one of this units. 

Introducing a predicate symbol = of sort (R.R), reflexive, symmetric and 
transitive, we foresee the need for the following principles: 

rl + r2 = r2 + rl 

(rl + r2) + r3 = rl + (r2 + r3) 

r + r = r 

r = s — » r < s (r — s) + s = r 
r = s^y(t — s = t — r) 
r = s^y(t + s= t + r) 
r = s — » ( O r A = O s A ) 

Due to space limitations it is not possible to present a full example of an 
organization and of a society of agents that includes that organizations. Exam- 
ples can be found in [14]. We conclude this section with some comments about 
the inclusion of delegations cases in the formal specification of organizations. 
We need to include a component in the structure of the organization describing 
the units that compose each role. Delegations that occur in an organization are 
included in the NR component of a society of agents that contains normative 
relations of the agents of the society. 

6 Conclusion and Future Work 

In this paper we discussed the concept of delegation in an organizational con- 
text. We considered role-based organizations - organizations structured by a 
set of roles, which are held by agents. Moreover, organizations are seen as nor- 
mative systems - a set of interacting agents whose behavior is ruled by norms 
(obligations, permissions and prohibitions) resultant from the deontic character- 
ization of the roles the agents’ hold. In that context, delegation is classified as a 
normative relation between agents, where agents transfer some (or all) of their 
deontic qualifications to other agents. A deontic and action modal logic has been 
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used to express the different interpretations of the delegation concept. This is a 
preliminary approach to delegation. Many open questions remain. 

One of the questions we intend to address is how to express the fact that 
not everything (obligations, permissions, powers of a role) may be object of del- 
egation. There are some cases where an obligation (permission) must be fulfilled 
directly by a particular agent in a role. A possible approach would be to dis- 
tinguish direct and indirect action, using, for example, a direct action operator 
like the one proposed in [17], D x , and adapted in [2] to direct actions of agents 
in roles. Using this operator we may express obligations that may be delegated 
from others that may not, using expressions similar to OE a:r A for the former 
and OD a:r for the latter. If this approach is adopted, we have to use impersonal 
obligations and permissions instead of the personal ones we have used in this 
paper. 

Another issue that needs further research is composition of roles. A formal 
study of the functions referred in the paper must be done. 

Other deontic concepts must be included in the characterization of delega- 
tion, specially the concept of power and representation. See [4], [15], for work on 
this issues. 

We are aware that, given its static nature, the type of logic proposed so far is 
not fully adequate to characterize the dynamic aspects referred in the previous 
delegation examples. There are in fact two relevant snapshots in the delegation 
process: before and after delegation. Before a delegation Delegate(x : rl,y : 
r2, r3) we naturally expect that agents x and y hold roles rl and r2 respectively, 
i.e. is—rl(x) and is—r2(y). However, after delegation, the deontic qualification of 
both agents may change and as a consequence it may happen that ~<is — rl(x) or 
-iis — r2(y). Obviously, these formulas together introduce a logical inconsistency. 
To overcome, this problem a possible approach would be to introduce temporal 
operators. 
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Abstract. We present an algorithm and its implementation for the verification of 
correct behaviour and epistemic states in multiagent systems. The verification is 
performed via model checking techniques based on OBDD’s. We test our imple- 
mentation by means of a communication example: the bit transmission problem 
with faults. 



1 Introduction 

In the last two decades, the paradigm of multiagent systems (MAS) has been employed 
successfully in several fields, including, for example, philosophy, economics, and soft- 
ware engineering. One of the reasons for the use of MAS formalism in such different 
fields is the usefulness of ascribing autonomous and social behaviour to the components 
of a system of agents. This allows to abstract from the details of the components, and 
to focus on the interaction among the various agents. 

Besides abstracting and specifying the behaviour of a complex system by means 
of MAS formalisms based on logic, recently researchers have been concerned with the 
problem of verifying MAS, i.e., with the problem of certifying formally that a MAS 
satisfies its specification. 

Formal verification has its roots in software engineering, where it is used to verify 
whether or not a system behaves as it is supposed to. One of the most successful for- 
mal approaches to verification is model checking. In this approach, the system S to be 
verified is represented by means of a logical model Ms representing the computational 
traces of the system, and the property P to be checked is expressed via a logical formula 
<pp. Verification via model checking is defined as the problem of establishing whether 
or not Ms \= ipp. Various tools have been built to perform this task automatically, and 
many real-life scenarios have been tested. 

Unfortunately, extending model checking techniques for the verification of MAS 
does not seem to be an easy task. This is because model checking tools consider stan- 
dard reactive systems, and do not allow for the representation of the social interaction 
and the autonomous behaviour of agents. Specifically, traditional model checking tools 
assume that M is “simply” a temporal model, while MAS need more complex for- 
malisms. Typically, in MAS we want to reason about epistemic, deontic, and doxastic 
properties of agents, and their temporal evolution. Hence, the logical models required 
are richer than the temporal model used in traditional model checking. 

A. Lomuscio and D. Nute (Eds.): DEON 2004, LNAI 3065, pp. 228-242, 2004. 
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Various ideas have been put forward to verify MAS. In [20], M. Wooldridge et al. 
present the MABLE language for the specification of MAS. In this work, non-temporal 
modalities are translated into nested data structures (in the spirit of [ 1]). Bordini et al. [2] 
use a modified version of the AgentSpeak(L) language [18] to specify agents and to ex- 
ploit existing model checkers. Both the works of M. Wooldridge et al. and of Bordini et 
al. translate the MAS specification into a SPIN specification to perform the verification. 
In this line, the attitudes for the agents are reduced to predicates, and the verification 
involves only the temporal verification of those. In [8] a methodology is provided to 
translate a deontic interpreted system into SMV code, but the verification is limited 
to static deontic and epistemic properties, i.e. the temporal dimension is not present, 
and the approach is not fully symbolic. The works of van der Meyden and Shilov [12], 
and van der Meyden and Su [13], are concerned with the verification of temporal and 
epistemic properties of MAS. They consider a particular class of interpreted systems: 
synchronous distributed systems with perfect recall. An automata-based algorithm for 
model checking is introduced in the first paper using automata. In [13] an example is 
presented, and [ 13] suggests the use of OBDD’s for this approach, but no algorithm or 
implementation is provided. 

In this paper we introduce an algorithm to model check MAS via OBDD’s. In par- 
ticular, in this work we investigate the verification of epistemic properties of MAS, and 
the verification of the “correct” behaviour of agents. 

Knowledge is a fundamental property of the agents, and it has been used for decades 
as key concept to reason about systems[5]. In complex systems, reasoning about the 
“correct” behaviour is also crucial. As an example, consider a client-server interaction 
in which a server fails to respond as quickly as it is supposed to a client’s requests. This 
is an unwanted behaviour that may, in certain circumstances, crash the client. It has been 
shown[ 14] that correct behaviour can be represented by means of deontic concepts: as 
we show in this paper, model checking deontic properties can help in establishing the 
extent in which a system can cope with failures. We give an example of this in Sec- 
tion 5.2, where two possible "faulty” behaviours are considered in the bit transmission 
problem[5], and key properties of the agents are analysed under these assumptions. In 
one case, the incorrect behaviour does not cause the whole system to fail; in the second 
case, the incorrect behaviour invalidates required properties of the system. We use this 
as a test example, but we feel that similar situations can arise in many areas, including 
database management, distributed applications, communication scenarios, etc. 

The rest of the paper is organised as follows. In Section 2 we review the formal- 
ism of deontic interpreted systems and model checking via OBDD’s. In Section 3 we 
introduce an algorithm for the verification of deontic interpreted systems. An imple- 
mentation of the algorithm is then discussed in Section 4. In Section 5 we test our 
implementation by means of an example: the bit transmission problem with faults. We 
conclude in Section 6. 



2 Preliminaries 

In this section we introduce the formalisms and the notation used in the rest of the paper. 
In Section 2. 1 we review briefly the formalism of interpreted systems as presented in [5] 
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to model a MAS, and its extension to reason about the correct behaviour of some of the 
agents as presented in [9], In Section 2.2 we review some model checking methodolo- 
gies. 



2.1 Deontic Interpreted Systems and Their Temporal Extension 

An interpreted system [5] is a semantic structure representing a system of agents. Each 
agent in the system i (i £ {1, . . . , n }) is characterised by a set of local states Li and by 
a set of actions Act; that may be performed. Actions are performed in compliance with 
a protocol P, : L; — > 2 Acti (notice that this definition allows for non-determinism). A 
tuple g = (li, £ L\ x ... , L n , where li £ Li for each i, is called a global state 

and gives a description of the system at a particular instance of time. Given a set I of 
initial global states , the evolution of the system is described by n evolution functions t, 
(this definition is equivalent to the definition of a single evolution function t as in [5]): 
t i : L\ x . . . x L n x Act\ x ... x Act n — -> L;. In this formalism, the environment 
in which agents "live” is usually modelled by means of a special agent E\ we refer 
to [5] for more details. The set I, the functions t *, and the protocols P t generate a set 
of computations (also called runs). Formally, a computation n is a sequence of global 
states 7 r = (go, g i, . . .) such that go £ I and, for each pair (gj, gj+i) £ n. there exists a 
set of actions a enabled by the protocols such that t(gj , a) = gj+\. G C (Li x . . . x L n ) 
denotes the set of reachable global states. 

In [9] the notion of correct behaviour of the agents is incorporated in this formalism. 
This is done by dividing the set of local states into two disjoint sets: a non-empty set 
Gi of allowed (or “green”) states, and a set R, of disallowed (or faulty, or "red”) states, 
such that Li = Gi U Ri, and G, fl R, = 0. Given a countable set of propositional 
variables V = {p, and a valuation function for the atoms V : V — ■> 2 G , a deontic 

interpreted systems is a tuple DIS = (G, ..., n }> {"<?}ie{i,...,n}> Rt, V). The 

relations are epistemic accessibility relations defined for each agent i by: g ~j g' 
iff li(g ) = li(g'), i.e. if the local state of agent i is the same in g and in g' (notice that 
this is an equivalence relation). The relations are accessibility relations defined by 
g Ap g' iff li(g') £ Gi, i.e. if the local state of i in g' is a “green” state. We refer 
to [9] for more details. The relation R t is a temporal relation between two global states. 
Deontic interpreted systems can be used to evaluate formulae involving various modal 
operators. Besides the standard boolean connectives, the language considered in [9] 
includes: 

- A deontic operator Oip, denoting the fact that under all the correct alternatives for 
agent i, p holds. 

- An epistemic operator Kip, whose meaning is agent i knows p. 

- A particular form of knowledge K \ p denoting the knowledge about a fact p that 
an agent i has on the assumption that agent j is functioning correctly. 

We extend this language by introducing the following temporal operators: 

EX(p), EG(p), E(pUip). Formally, the language we use is defined as follows: 

p::=p \->p\pV p\ EXp \ EGp \ E(pUp) \ Ki(p) \ Oi(p) \ K f (p) 
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We now define the semantics for this language. Given a deontic interpreted system 
DIS, a global state g, and a formula p, satisfaction is defined as follows: 

DIS,g^p iff j6V(p), 

DIS,g \= -up i&gfip, 

DIS, g f= pi V pi iff g |= Pi °r 9 b V? 2 , 

DIS, g \= EX p iff there exists a computation 7r such that no = g and m |= ip, 

DIS, g \= EGp iff there exists a computation n such that no = g and m |= <p 

for all i > 0. 

DI S,g f= E(ipUip) iff there exists a computation n such that no = g and a k > 0 such 
that nk {= and ni \= p for all 0 < i < k, 

DIS,g \= Kap iff Vg' € G, g g' implies g' |= <p 

DIS,g \= Onp iff Mg' £ G, g A? g' implies g' \= ip 

DIS, g \= Kf ip iff \/g ’ £ G, g ~i g' and g -<f g' implies g' \= tp 

In the definition above, n 3 denotes the global state at place j in computation n. Other 
temporal modalities can be derived, namely AX, EF, AF, AG, AU . We refer to [5, 9, 
15] for more details. 

2.2 Model Checking Techniques 

The problem of model checking can be defined as establishing whether or not a model 
M satisfies a formula p (M |= tp). Though M could be a model for any logic, tradition- 
ally the problem of building tools to perform model checking automatically has been 
investigated almost only for temporal logics [4, 7]. 

The model M is usually represented by means of a dedicated programming lan- 
guage, such as PROMELA[6] or SMV[11], The verification step avoids building the 
model M explicitly from the program; instead, various techniques have been inves- 
tigated to perform a symbolic representation of the model and the parameters needed 
by verification algorithms. Such techniques are based on automata [6], ordered binary 
decision diagrams (OBDD’s, [3]), or other algebraic structures. These approaches are 
often referred to as symbolic model checking techniques. For the purpose of this paper, 
we review briefly symbolic model checking using OBDD’s. 

It has been shown that OBDD’s offer a compact representation of boolean functions. 
As an example, consider the boolean function a A (6Vc). The truth table of this function 
would be 8 lines long. Equivalently, one can evaluate the truth value of this function by 
representing the function as a directed graph, as exemplified on the left-hand side of 
Figure 1 . As it is clear from the picture, under certain assumptions, this graph can be 
simplified into the graph pictured on the right-hand side of Figure 1 . This “reduced” 
representation is called the OBDD of the boolean function. Besides offering a compact 
representation of boolean functions, OBDD’s of different functions can be composed 
efficiently. We refer to [3, 1 1] for more details. 

The key idea of model checking temporal logics using OBDD’s is to represent the 
model M and all the parameters needed by the algorithms by means of boolean func- 
tions. These boolean functions can then be encoded as OBDD’s, and the verification step 
can operate directly on these. The verification is performed using fix-point character- 
isation of the temporal logics operators. We refer to [7] for more details. Using this 
technique, systems with a state space in the region of 10 40 have been verified. 
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Fig. 1. OBDD representation for a A (b V c). 



3 Model Checking Deontic Properties of Interpreted Systems 

In this section we present an algorithm for the verification of deontic, epistemic, and 
temporal modalities of MAS, extending with deontic modalities the work that appeared 
in [17]. Our approach is similar, in spirit, to the traditional model checking techniques 
for the logic CTL. Indeed, we start in Section 3. 1 by representing the various parameters 
of the system by means of boolean formulae. In Section 3.2, we provide and algorithm 
based on this representation for the verification step. The whole technique uses deontic 
interpreted systems as its underlying semantics. 



3.1 From Deontic Interpreted Systems to Boolean Formulae 

In this section we translate a deontic interpreted system into boolean formulae. As 
boolean formulae are built using boolean variables, we begin by computing the re- 
quired number of boolean variables. To encode local states of an agent, the number of 
boolean variables required is nv(i) = \l 0 g 2 \Li\]. To encode actions, the number of 
variables required is na(i ) = \l 0 g 2 \Acti\] . Hence, given N = nv(i), a global state 

i 

can be encoded by means N boolean variables: g = (vi, . . . ,vn)- Similarly, given 
M = na(i ), a joint action can be encoded as a = (ai, . . . , oju). 

i 

Having encoded local states, global states, and actions by means of boolean vari- 
ables, all the remaining parameters can be expressed as boolean functions as follows. 
The protocols relate local states to set of actions, and can be expressed as boolean for- 
mulae. The evolution functions can be translated into boolean formulae, too. Indeed, the 
definition of t % in Section 2.1 can be seen as specifying a list of conditions c^i, . . . , fo- 
under which agent i changes the value of its local state. Each c v/ has the form “if [con- 
ditions on global state and actions] then [value of “next” local state for *]”. Hence, tj 
is expressed as a boolean formula as follows: ti = c», 1 © ... © c-ik where © denotes 
exclusive-or. We assume that the last condition of ti prescribes that, if none of the 
conditions on global states and actions in Cj j (j < k) is true, then the local state for 
i does not change. This assumption is key to keep compact the description of the sys- 
tem, so that only the conditions causing a change in the configuration of the system 
need to be listed. The evaluation function V associates a set of global states to each 
propositional atom, and so it can be translated into a boolean function. 
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In addition to these parameters, the algorithm presented in Section 3.2 requires the 
definition of a boolean function R t (g,g') representing a temporal relation between g 
and g’ . Rt(g , </) can be obtained from the evolution functions tj as follows. First, we 
introduce a global evolution function t : 

t= f\ U= /\ (c a e...®Ci, fei ) 

Notice that t is a boolean function involving two global states and a joint action a = 
(ai, . . . , Om)- To abstract from the joint action and obtain a boolean function relating 
two global states only, we can define R t as follows: 

R t (g, g') iff 3a G Act : t(g, a, g') is true and each local action a, £ a is enabled by the 
protocol of agent i in the local state l{(g). 

The quantification over actions above can be translated into a propositional formula 
using a disjunction (see [11,4] for a similar approach to boolean quantification): 

Rt(g,g')= [(t(g,a,g') A P(g,a)} 

a(z Act 



where P(g, a) is a boolean formula imposing that the joint action a must be consistent 
with the agents’ protocols in global state g. The relation R t gives the desired boolean 
relation between global states. 



3.2 The Algorithm 

In this section we present the algorithm SAT (ip) to compute the set of global states in 
which a formula ip holds. The following are the parameters needed by the algorithm: 

- the boolean variables (iq, . . . , Vn ) and (ai, . . . , am) encoding global states and 
joint actions; 

- n boolean functions Pi(v\, . . . , Vn, ai, . . . , om) encoding the protocols of the 
agents; 

- the function V(p) returning the set of global states in which the atomic proposition 
p holds. We assume that the global states are returned encoded as a boolean function 

of (vi, . . .,v N ); 

- the set of initial states J, encoded as a boolean function; 

- the set of reachable states G. This can be computed as the fix-point of the operator 
r = (1(g) V 3g'(R t (g' , g) A Q(g ')) where 1(g) is true if g is an initial state and Q 
denotes a set of global states. The fix-point of r can be computed by iterating t( 0) 
by standard procedure (see [11]); 

- the boolean function R t encoding the temporal transition; 

- n boolean functions Ri encoding the accessibility relations (these functions are 
defined using equivalence on local states of G); 

- n boolean functions Rf encoding the deontic accessibility relations 
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The algorithm is as follows: 



SAT (ip) { 

ip is an atomic formula: return V(ip)\ 

ip is -iipi : return G \ SAT [ip i); 

ip is pi A ip 2 \ return SAT(ipi) H SAT(ip 2 )\ 

ip is EXipp. return SATex(p i); 

ip is E[(p\Uip 2 )'- return SATEu[ipi,ip 2 )', 

ip is EGipp. return SAT E g(Pi)\ 

(pis Kopy. return SATk (pi, *); 
ip is Oupy return SATo[(pi, i); 
ip is K 1 ipy return SAT K H(ipi,i,j ); 

} 



In the algorithm above, SATex , SATeg , SATejj are the standard procedures for 
CTL model checking [7], in which the temporal relation is R t and, instead of tempo- 
ral states, global states are considered. The procedures SATk(p>, i), SATo(ip, i ) and 
SATkh(Ti j) return a set of states in which the formulae Kpp, Oip and K\ ip are 
true. Their implementation is presented below. 



SATk(<p, i) { 

X = SAT(-iip)\ 

Y = {<? £ G\3g' € X and Ri(g, g')} 
return ->Y; 

} 



SAT 0 (ip,i) { 

X = SAT(^<py, 

Y = {geG\3g’ ex md R?(g,g')} 
return -iY; 

} 



SATkh(p,T) { 

X = SAT(ip)- 

Y = {g e G\3g' e X and Ri(g,g') and Rf ( g,g ')} 
return -iY; 

} 



Notice that all the parameters can be encoded as OBDD’s. Moreover, all the operations 
in the algorithms can be performed on OBDD’s. 

The algorithm presented here computes the set of states in which a formula holds, 
but we are usually interested in checking whether or not a formula holds in the whole 
model. SAT (ip) can be used to verify whether or not a formula ip holds in a model by 
comparing two set of states: the set SAT(ip) and the set of reachable states G. As sets 
of states are expressed as OBDD’s, verification in a model is reduced to the comparison 
of the two OBDD’s for SAT(ip) and for G. 
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4 Implementation 

In this section we present an implementation of the algorithm introduced in Section 3. 
In Section 4. 1 we define a language to encode deontic interpreted systems symbolically, 
while in Section 4.2 we describe how the language is translated into OBDD’s and how 
the algorithm is implemented. The implementation is available for download[16]. 

4.1 How to Define a Deontic Interpreted System 

To define a deontic interpreted system it is necessary to specify all the parameters pre- 
sented in Section 2.1. In other words, for each agent, we need to represent: 

- a list of local states, and a list of “green” local states; 

- a list of actions; 

- a protocol for the agent; 

- an evolution function for the agent. 

In our implementation, the parameters listed above are provided via a text file. The 
formal syntax of a text file specifying a list of agents is as follows: 

agentlist ::= agentdef | 

agentlist agentdef 
agentdef ::= "Agent" ID 

LstateDef ; 

LgreenDef ; 

ActionDef ; 

ProtocolDef ; 

EvolutionDef ; 

"end Agent" 



LstateDef : : = 


"Lstate = 


{" 


IDLIST 


II | II 


LgreenDef : : = 


"Lgreen = 


{" 


IDLIST 


II J II 


ActionDef : : = 


"Action = 


{" 


IDLIST 


II J II 


ProtocolDef : 


= "Protocol" 








ID " : 


{" 


IDLIST 


II J II 



"end Protocol" 

EvolutionDef ::= "Ev: " 

ID "if" BOOLEANCOND; 

" end Ev" 

IDLIST : := ID | 

IDLIST "," ID 

ID ::= [a-zA-Z] [a-zA-Z0-9_] * 

In the definition above, BOOLEANCOND is a string expressing a boolean condition; we 
omit its description here and we refer to the source code for more details. To com- 
plete the specification of a deontic interpreted system, it is also necessary to define the 
following parameters: 
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- an evaluation function; 

- a set of initial states (expressed as a boolean condition); 

- a list of subsets of the set of agents to be used for particular group modalities 

The syntax for this set of parameters is as follows: 

EvaluationDef ::= "Evaluation" 

ID "if" BOOLEANCOND; 

"end Evaluation" 

InitstatesDef ::= "InitStates" 

BOOLEANCOND ; 

"end InitStates" 

GroupDef ::= "Groups" 

ID " = {" IDLIST " 

"end Groups" 

Due to space limitations we refer to the hies available online for a full example of 
specification of an interpreted system. 

Formulae to be checked are specified using the following syntax 

formula ::= ID | 

formula "AND" formula | 

"NOT" formula | 

"EX ( " formula " ) " | 

"EG ( " formula " ) " | 



E ( " 


formula 


"U" formula ")" | 


K ( " 


ID " , " 


formula "] 


i" | 


0(" 


ID " , " 


formula "] 


i" | 


KH ( 


" ID " , 


Q 

H 


formula ")" 



Above, K denotes knowledge of the agent identified by the string ID; 0 is the deontic 
operator for the agent identified by ID. To represent the knowledge of an agent under 
the assumption of correct behaviour of another agent we use the operator KH followed 
by an identifier for the first agent, followed by another identifier for the second agent, 
and a formula. 

4.2 Implementation of the Algorithm 

Figure 2 lists the main components of the software tool that we have implemented. 
Steps 2 to 6, inside the dashed box, are performed automatically upon invocation of the 
tool. These steps are coded mainly in C++ and can be summarised as follows: 

- In step 2 the input hie is parsed using the standard tools Lex and Yacc. In this 
step various parameters are stored in temporary lists; such parameters include the 
agents’ names, local states, actions, protocols, etc. 

- In step 3 the lists obtained in step 2 are traversed to build the OBDD’s for the ver- 
ification algorithm. These OBDD’s are created and manipulated using the CUDD 
library [19]. In this step the number of variables needed to represent local states 
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1. Specify an interpreted system ** Any text editor 




Fig. 2. Software structure. 



and actions are computed; following this, all the OBDD’s are built by translating the 
boolean formulae for protocols, evolution functions, evaluation, etc. Also, the set 
of reachable states is computed using the operator presented in Section 3.2. 

- In steps 4 the formulae to be checked are read from a text file, and parsed. 

- In step 5 the verification is performed by implementing the algorithm of Section 3.2. 
At the end step 5, an OBDD representing the set of states in which a formula holds 
is computed. 

- In step 6, the set of reachable states is compared with the OBDD corresponding to 
each formula. If the two sets are equivalent, the formula holds in the model and the 
tools produce a positive output. If the two sets are not equivalent, the tool produces 
a negative output. 



5 An Example: The Bit Transmission Problem with Faults 

In this section we test our implementation by verifying temporal, epistemic and deontic 
properties of a communication example: the bit transmission problem [5]. 

The bit-transmission problem involves two agents, a sender S, and a receiver R, 
communicating over a faulty communication channel. The channel may drop messages 
but will not flip the value of a bit being sent. S wants to communicate some information 
(the value of a bit) to R. One protocol for achieving this is as follows. S immediately 
starts sending the bit to R, and continues to do so until it receives an acknowledgement 
from R. R does nothing until it receives the bit; from then on it sends acknowledge- 
ments of receipt to S. S stops sending the bit to R when it receives an acknowledge- 
ment. 
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This scenario is extended in [10] to deal with failures. In particular, here we assume 
that R may not behave as intended perhaps as a consequence of a failure. There are 
different kind of faults that we may consider for R. Following [10], we discuss two 
examples; in the first, R may fail to send acknowledgements when it receives a message. 
In the second, R may send acknowledgements even if it has not received any message. 

In Section 5.1, we give an overview of how these scenarios can be encoded in the 
formalism of deontic interpreted systems. This section is taken from [10]. In Section 5.2 
we verify some properties of this scenario with our tool, and we give some quantitative 
results about its performance. 

5.1 Deontic Interpreted Systems for the Bit Transmission Problem 

It is possible to represent the scenario described above by means of the formalism of 
deontic interpreted systems, as presented in [ 10, 8]. To this end, a third agent called E 
(environment) is introduced, to model the unreliable communication channel. The local 
states of the environment record the possible combinations of messages that have been 
sent in a round, either by S or R. Hence, four possible local states Le are taken for 
the environment: Le = {(., .), ( sendbit , .), (., sendack), ( sendbit , sendack )}, where 
V represents configurations in which no message has been sent by the corresponding 
agent. The actions ActE for the environment correspond to the transmission of mes- 
sages between S and R on the unreliable communication channel. It is assumed that 
the communication channel can transmit messages in both directions simultaneously, 
and that a message travelling in one direction can get through while a message travel- 
ling in the opposite direction is lost. The set of actions ActE for the environment is: 
ActE = {S—R, S— *, <— R, — }. “S—R" represents the action in which the channel 
transmits any message successfully in both directions, “S—>” that it transmits success- 
fully from S to R but loses any message from R to S, R" that it transmits suc- 
cessfully from R to S but loses any message from S to R, and ” that it loses any 
messages sent in either direction. We assume the following constant function for the 
protocol of the environment, Pe : 

Pe(Ie) — ActE = {S—R, S — *, < — R, — }, for all Ie € Le- 

The evolution function for E is reported in Table 1 . 

Table 1. Transition conditions for E. 



Final state 


Transition condition 




Acts = A and Actn = A 


( sendbit , .) 


Acts = sendbit (0) and Actn = A or 
Acts = sendbit (1 ) and Act r = A 


(., sendack ) 


Acta = A and Acta = sendack 


( sendbit , sendack) 


Acts = sendbit (0) and Acta = sendack or 
Acts = sendbit(l) and Acta = sendack 



We model sender S by considering four possible local states. They represent the 
value of the bit S is attempting to transmit, and whether or not S has received an ac- 
knowledgement from R: Lg = {0, 1, (0, ack ), (1, ack)}. The set of actions Acts for S 
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is: Acts = {sendbit(O), sendbit(l), A}, where A denotes a null action. The protocol 
for S is defined as follows: 

.Pg(O) = sendbit(0 ), Ps(l) = sendbit( 1), 

Ps((0, ack)) = Ps((l, ack)) = A. 

The transition conditions for S are listed in Table 2. 

Table 2. Transition conditions for S. 



Final state 


Transition condition 


(0, ack) 


Ls = 0 and Act R = sendack and ActE = S—R or 
Ls = 0 and Act R = sendack and ActE = <— R 


(1, ack) 


Ls = 1 and Act R = sendack and ActE = S—R or 
Ls = 1 and Act R = sendack and ActE = <— R 



We now consider two possible faulty behaviours for R, that we model below. 

Faulty receiver - 1. In this case we assume that R may fail to send acknowledgements 
when it is supposed to. To this end, we introduce the following local states for R: 
L' r = {0, 1, e, (0, /), (1, /)}. The state “e” is used to denote the fact that R did not 
receive any message from S; “0” and “1” denote the value of the received bit. The 
states “(i, /)” (* = {0, 1}) ar e faulty or red states denoting that, at some point in the 
past, R received a bit but failed to send an acknowledgement. The set of allowed actions 
for R is: Act r = { sendack , A}. The protocol for R is the following: 

P' R (t) = A, P R (0) = P' R { 1) = {sendack, A}, P R ((0, /)) = P^((l,f)) = {sendack, A}. 

The transition conditions for R are listed in Table 3. 

Table 3. Transition conditions for R. 



Final state 


Transition condition 


0 


Acts = sendbit(O) and L R = e and ActE = S—R or 
Acts = sendbit(O) and L R = t and ActE = S'— > 


1 


Acts = sendbit(l) and L R = e and ActE = S—R or 
Acts = sendbit(l) and L R = t and ActE = S^> 


(0,/) 


L r = 0 and Act R — e 


(1 ,/) 


L r = 1 and Act R — e 



Faulty receiver - 2. In this second case we assume that R may send acknowledgements 
without having received a bit first. We model this scenario with the following set of local 
states L" r for R: 

Lr = {0, 1, e, (0, /), (1, /), (e, /)}. 

The local states “e”, “0”, “1”, “(0, /)” and ”(1, /)” are as above; “(e, /)” is a further 
faulty state corresponding to the fact that, at some point in the past, R sent an acknowl- 
edgement without having received a bit. The actions allowed are the same as in the 
previous example. The protocol is defined as follows: 
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Pr{z) = ^ 

P"(0) = -Pfl(l) = sendack , 

^((0, /)) = Pg((l, /)) = Pg((e, /)) = {sendacfc, A}. 

The evolution function is reported in Table 4. 

Table 4. Transition conditions for f?.. 



Final state 


Transition condition 


0 


Acts = sendbit(O) and Lr = e and ActE = S—R or 
Acts = sendbit(O) and Lr = e and ActE = S— > 


1 


Acts = sendbit(l) and Lr = e and ActE = S—R or 
Acts = sendbit(l) and Lr = e and ActE = S^> 


(e, /) 


Lr = t and ActR = sendack 


(0,/) 


Acts = sendbit(O) and Lr = (e, /) and ActE = S—R or 
Acts = sendbit(O) and Lr = (e, /) and ActE = S — > 


(1,/) 


Acts = sendbit(l) and Lr = (e, /) and ActE = S—R or 
Acts = sendbit(l) and Lr = (e, /) and ActE = S — > 



For both examples, we introduce the following evaluation function: 

V(bit = 0) = {g £ G\ls(g) = 0 or ls(g) = (0, ack )} 

V(bit = 1) = {g £ G\l s (g) = 1 or l s (g) = (1, ack)} 

V(recbit) = {g £ G\l R {g) = 1 or l R (g) = 0} 

V(recack) = {g £ G\l s (g) = (1 ,ack) or l s (g) = (0,acfc)} 

The evaluation function V and the parameters above generate two deontic interpreted 
systems, one for each faulty behaviour of R\ we refer to these deontic interpreted sys- 
tems as DIS i and DIS 2 . 

It is now possible to express formally properties of these scenarios by means of the 
language of Section 2. 1 . 

A{->{Ks(Kr (bit = 0) V K ft (bit = 1))) U recack) (1) 

A(-,(K§(K r (bit = 0) V I<R (bit = 1))) U recack) (2) 

Formula 1 above captures the fact that S will not know that R knows the value of 
the bit, until S receives an acknowledgement. Formula 2 expresses the same idea but by 
using knowledge under the assumption of correct behaviour. In the next section we will 
verify in an automatic way that Formula 1 holds in DIS 1 but not in DIS 2 . This means 
that the faulty behaviour of R in DIS 1 does not affect the key property of the system. 
On the contrary, Formula 2 holds in both DIS 1 and DIS 2 ', hence, a particular form of 
knowledge is retained irrespective of the fault. 

5.2 Experimental Results 

We have encoded the deontic interpreted system and the formulae introduced in the 
previous section by means of the language defined in Section 4. 1 (a copy of the code 
is included in the downlodable files). The two formulae were correctly verified by the 
tool for DIS 1 , while Formula 1 failed in DIS 2 as expected. 
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To evaluate the performance of our tool, we first analyse the space requirements. 
Following the standard conventions, we define the size of a deontic interpreted system 
as \DIS\ = | + |i?|, where |Sj is the size of the state space and |i?| is the size of 
the relations. In our case, we define |Sj as the number all the possible combinations of 
local states and actions. In the example above, there are 4 local states and 3 actions for 
S, 5 (or 6) local states and 2 actions for R, and 4 local states and 4 actions for E. In 
total we have |Sj « 2 • 10 3 . To define \R\ we must take into account that, in addition 
to the temporal relation, there are also the epistemic and deontic relations. Hence, we 
define \R\ as the sum of the sizes of temporal, epistemic, and deontic relations. We 
approximate \R\ as \S\ 2 , hence \M\ = |Sj + \R\ « | 2 « 4 • 10 6 . 

To quantify the memory requirements we consider the maximum number of nodes 
allocated for the OBDD’s. Notice that this figure over-estimates the number of nodes 
required to encode the state space and the relations. Further, we report the total memory 
used by the tool (in MBytes). The formulae of both examples required a similar amount 
of memory and nodes. The average experimental results are reported in Table 5. 



Table 5. Memory requirements. 



\M\ 


obdd’s nodes 


Memory (MBytes) 


« 4 • l(f 


« 10 3 


« 4.5 



In addition to space requirements, we carried out some test on time requirements. 
The running time is the sum of the time required for building all the OBDD’s for the 
parameters and the actual running time for the verification. We ran the tool on a 1 .2 GHz 
AMD Athlon with 256 MBytes of RAM, running Debian Linux with kernel 2.4.20. The 
average results are listed in Table 6. 



Table 6. Running time (for one formula). 



Model construction 


Verification 


Total 


0.045sec 


<0.01sec 


0.05sec 



We see these as very encouraging results. We have been able to check formulae with 
nested temporal, epistemic and deontic modalities in less than 0. 1 seconds on a standard 
PC, for a non-trivial model. Also, the number of OBDD’s nodes is orders of magnitude 
smaller than the size of the model. Therefore, we believe that our tool could perform 
reasonably well even in much bigger scenarios. 

6 Conclusion 

In this paper we have extended a major verification technique for reactive systems — 
symbolic model checking via OBDD’s — to verify temporal, epistemic, and deontic 
properties of multiagent systems. We provided an algorithm and its implementation, and 
we tested our implementation by means of an example: the bit transmission problem 
with faults. The results obtained are very encouraging, and we estimate that our tool 
could be used in bigger examples. For the same reason, we see as feasible an extension 
of the tool to include other modal operators. 
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Abstract. In this paper we investigate the specification and verification of infor- 
mation systems with an organizational structure. Such systems are modelled as 
a normative multiagent system. To this end we use KBDIOctl* an extension of 
BDIctl in which obligations and permissions are represented by directed modal 
operators. We illustrate how the logic can be used by introducing and discussing 
various properties of normative systems and individual agents which can be rep- 
resented in the logic. In particular we discuss the enforcement of norms. 



1 Introduction 

Normative computer systems are computer systems which involve obligations, prohi- 
bitions and permissions [1], The traditional applications can be found in computer se- 
curity, for example to regulate access to file systems or libraries. Other applications 
have been studied in electronic commerce, in legal expert systems and in databases. 
See [2] for a survey on these applications. More recently, normative systems have been 
used to regulate virtual communities in the context of the (semantic) web. To support 
the development of such systems, several agent architectures have been proposed that 
incorporate obligations, prohibitions and permissions. 

In this paper we investigate the formalization of regulations such as the widely dis- 
cussed library regulations, parking regulations, copier regulations, cottage regulations, 
et cetera. Such examples are characterized by sometimes complicated normative sys- 
tems, as well as organizational structures. Moreover, in contrast to earlier investigations, 
we not only consider the case in which humans interact with a normative computer 
system, but we also consider cases in which computers interact with other computer 
systems, that is, we consider multiagent systems. In particular, we consider the formal- 
ization of properties involving normative multiagent systems in an extension of Schild’s 
BDIctl [3-5], which is itself a variant of Rao and Georgeff’s BDIctl [6], Such an ex- 
tension consists of an extension of the logic and an extension of the properties expressed 
in the logic. Obligations are motivational attitudes, just like desires, but they are also 
related to organizational issues. 

First, obligation is formalized as a directed modality [7-1 1], Thus, whereas we may 
say that agent a desire to prepare a report, we say that the agent a is obliged to prepare 
a report towards another agent h. Moreover, as explained in more detail in Section 5, 
whereas desires and intentions remain in force as motivational attitude until the agent 
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believes they have been achieved or are no longer achievable, obligations remain in 
force until the agent knows they have been fulfilled or they are no longer achievable. 
We introduce an extension of BDI CTL called KBDIOctl, that makes the distinction 
between desires and obligations explicit, as well as the distinction between beliefs and 
knowledge. 

Second, we provide organizational concepts such as roles, role relations, and groups 
in order to specify inter-agent relations that hold in organizations. The organizational 
concepts are interpreted as follows. 



A role is a set of related constraints that should be satisfied when an agent enacts the 
role. For example, the role of project manager puts constraints on the expertise, 
capabilities, responsibilities, goals, obligations and permissions of the agent that 
enacts the role. Note that various different definitions of the concept of a role have 
been proposed. Our definition follows [12-15]. The definition of a role is always 
related to some organizational activity, which determines its scope. For example, 
the role of chairman only makes sense during a meeting. Agents may only enact a 
role provided they are qualified, i.e., meet the basic requirements for the role. 

Role relations, also known as dependencies or channels, are constraints put on a rela- 
tion between roles. Examples of a role relations are supervisor jof and the producer- 
consumer relation. Role relations coordinate the behavior of different agents, simi- 
lar to the way channels coordinate components in software architectures [16]. One 
role can be enacted by many agents. Consider for example several postmen in a 
district. Moreover, one agent can enact many roles. Consider for example a lecturer 
who is also a conference reviewer. 

A group is a set of roles that share a group characteristic. For example, roles involved 
in selling goods in an organization form a group often called the selling department. 

The motivation of our work is to develop a specification and verification language 
for normative multiagent systems with organizational structure. We therefore focus on 
properties of regimentation, which formalize whether norms can be violated, on dead- 
lines, and on definitions of organizational structure. Due to the fact that we not only 
consider humans, but also artificial agents interacting with normative computer sys- 
tems, new issues and properties arise. 

For example, for agent systems it is common practice to design agents that can- 
not violate norms, or agents that are benevolent and will always first try to fulfill the 
obligations or goals of other agents, before trying to achieve their own desires. There- 
fore it is useful to have a specification language that can express such properties too. 
As these properties cannot be programmed in human agents, such properties have not 
made sense previously, and consequently we believe that they have not been addressed 
in the literature. We acknowledge the criticism on such properties, but such criticism is 
beyond the scope of this paper. 

The layout of the paper is as follows. In section 2 we describe an example speci- 
fication domain. In Section 3 we extend Schild’s logic with obligations, prohibitions, 
permissions and organizational concepts. In the remainder, we discuss properties which 
can be expressed in the logic, and which can be used to specify the running example. 
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2 Multiagent Organizations: The Running Example 



In this section we exemplify the type of specification properties we are interested in. 
Shorter specification examples in subsequent sections will also apply to the domain 
described here. Our example domain is concerned with the different ways an organiza- 
tional norm can be implemented in a multiagent system. A multiagent system developer 
has a choice of options to operationalize a norm. In each case, a number of assumptions 
about the mental attitudes and reasoning capabilities of the subjects of the norm, the 
individual agents, are necessary. A system developer can leave it up to the individ- 
ual agents to respect the norm. In that case, he assumes that agents are benevolent or 
norm-abiding, and proving that the system comforms to the norm presupposes that this 
assumptions is formalized. By contrast, the system developer can hardwire the norm 
into the environment, making it physically impossible for agents to violate it. In that 
case, no additional assumptions on agents are needed. We believe that a rich logic like 
KBDIOc n is suitable to express this kind of notions and assumptions. 

The example is derived from an observation concerning different ticket policies 
of public transport networks [17]. Suppose ticket policies are specified as a multi-agent 
system. Using these specifications, one can formulate the consequences of such policies 
as logical properties, and verify them with respect to the system specifications. 

Compare the Paris metro with a French train. On the entrance of a platform of the 
Paris metro, the authorities have placed a high barrier with gates that will only open 
when a valid ticket is inserted. Without a valid ticket, it is physically impossible to 
pass the barrier and use the metro. By contrast, it is possible to board a French train 
without a ticket. The authorities rely on personal benevolence, on social pressure, and 
on a sanctioning system of ticket inspection and fines, to persuade passengers to buy 
a valid ticket. Looking at other travel systems we find yet other solutions to the same 
problem: under which assumptions can we conclude that all passengers will pay for the 
ride? We can phrase the norm as follows: 

When travelling by public transport, one should have paid for the trip. 

This norm is an instance of a much more general pattern occurring in situations in 
which humans interact with normative computer systems, and also in multiagent sys- 
tems such as virtual communities or web services. For example, an agent has to access 
a resource offered by another agent. To regulate such access, there is an organizational 
structure, that may contain roles, but also more complicated normative constructs such 
as authorization and delegation mechanisms. In this paper we restrict ourselves to the 
norm above. 

We consider the following ways to implement this norm in a multi-agent system. 
Each possibility relies on some specific assumptions about the environment, or about 
the agents inhabiting the system. 

1 . Implementing a norm in the environment. The norm is enforced with gates on 
the platform. No assumptions on the mental attitudes of agents are needed, only 
assumptions about their physical ability. 
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2. Implementing a norm by designing benevolent or norm abiding agents. All 

agents can be designed to be sincere. If they tell you they have paid, you can trust 
them. This removes the need for tickets as evidence of payment. Moreover, agents 
can be designed to be either benevolent, or norm abiding. If a benevolent agent 
understands why the norm is a good norm, for example to maintain a good quality 
of public transport, it will internalize the norm and make it a personal goal. A norm 
abiding agent will simply obey the norm, no matter how this relates to its own goals. 

3. Implementing a norm by relying on rationality. Here tickets are introduced as 
evidence of payment, and hence as a right to travel. No sincerity assumption is 
needed. If an agent is caught travelling without a valid ticket, it is subject to a sanc- 
tion: to pay a fine. This assumes that agents are rational decision makers, in the 
economic sense of maximizing expected utility. An agent will display the behavior 
corresponding to the norm, if a ticket is cheaper than the fine multiplied by the per- 
ceived chance of being caught. Authorities can affect this way of decision making 
by increasing the fine, or by making the agents believe that the chance of being 
caught has increased. 

4. Implementing a norm by relying on social control. Here again tickets are used as 
evidence of payment. Being caught without a ticket leads to social embarrassment 
and a loss of reputation. Like in item 3 above, this solution assumes that agents are 
subject to sanctions, and moreover, that embarrassment counts as an effective sanc- 
tion. Embarrassment typically only comes up if all other passengers can observe 
that the passenger does not pay. 

5. Implementing a norm by relying on a combination of mechanisms. In most 
actual situations a mixture of these types of norm enforcement is in place. For 
example, a fine system is used to remind agents of the noble purpose behind the 
norm. Social embarrassment comes on top of the fine. That means that in practice, 
fines do not have to be as high as would be required for socially unaffected citizens. 

Note that the above categories not only occur in human society, but also in multia- 
gent systems. Implementing a norm in the environment is also the typical case used 
in web services: if an agent has not paid for the service, it simply cannot access it. 
Implementing a norm by norm abiding agents is not possible in human organizations, 
but frequently occurs in multiagent organizations. Human and multiagent systems of- 
ten depend on rationality, for example in the context of electronic commerce. Finally, 
many human organizations rely on social control, and there are examples of multiagent 
systems containing social agents [18]. 

Obligations are motivational attitudes, just like desires, but they also have orga- 
nizational aspects. First, obligations are always directed. Obligations can be directed 
towards abstract entities like ‘the company’ or ‘the system’, towards other agents, or 
towards the agents themselves. Second, the organizational structure is represented by 
the sets of roles, groups, and their interactions, as indicated above. Group membership 
and the assignment of agents to roles changes over time, as role relations are estab- 
lished or disconnected. The ‘social fact’ of an agent enacting a role is distinguished 
from the satisfaction of the requirements that go with the role. For example, although a 
passenger does not have a ticket while he is in the metro, even if he does not satisfy the 
requirements set by the role, he remains a passenger. 
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3 KBDIO ctl , a Logic for Specifying Muitiagent Organizations 

We use a version of BDIctl presented by Schild [3], which we extend with operators 
for knowledge and directed obligation. The syntax of KBDIOcTijnvolves a modal op- 
erator K a for knowledge of agent a, an operator B a for belief, I)„ for desire, I a for 
intention, and O a ,b for an obligation of agent a towards agent b [7, 8, 10, 11], Knowl- 
edge, belief, desire and intention are internal to the agent and thus not directed. The 
temporal operators of the language are imported from CTL. To specify organizational 
structure, special propositions 'g(ci)', ‘r(a)\ and ‘a ch b ' are introduced for ‘agent a is 
a member of group g\ ‘agent a enacts role r\ and ‘agent a and b stand in role relation 
ch ' , respectively. Higher order relations can be defined analogously. We assume that 
roles, groups and role relations are all primitive, though in certain systems they have 
been defined in terms of each other. For example, a group can be defined as the role of 
being a member of the group. Also, a group can be defined as a role relation between 
all members of the group, or between the group members and the group leader. 

Definition 1 (Syntax KBDIOctl)- Given a finite set A of agent names, a finite set 
G of group names, a finite set R of role names, a finite set C of role relations, and 
a countable set P of primitive proposition names, which includes ‘g(a)’, V(a)’, and 
‘a ch b’ for all a,b £ A, g £ G, r £ R, and ch £ C, the admissible formulae of 
KBDIOctl are recursively defined by: 

51 Each primitive proposition in P is a state formula. 

52 If a and (3 are state formulae, then so are a A (3 and ~<a. 

53 If a is a path formula, Ea and Aa are state formulae. 

54 If a is a state formula and a,b £ A, then K a (a), B a (a), D a (a), I a (a), O a ,b(cf) 
are state formulae as well. 

P If a and (3 are state formulae, then Xa and aU (3 are path formulae. 

We assume the following abbreviations: 

disjunction a V (3 =def _l (^a A ~>/3) implication a — > (3 = de f ~<a\/ /3 

future F(a) = de f ZUa globally G(a) = de f ->F(-ia ) 

permission P a ,b{a) =def ~^O a ^a) prohibition F a>6 (a) = def ~^P a ,b(a) 

undirected O a (a) = de f O a , a (a). 

The semantics of KBDIOctl involves two dimensions. The truth of a formula is evalu- 
ated relative to a world w and a temporal state s. A pair (w, s) is called a situation. The 
relation between situations is traditionally called an accessibility relation (for beliefs) 
or a successor relation (for time). 

Definition 2 (Situation structure KBDIOctl)- Assume a finite set A of agent names. 
A structure M = (A, TZ,IC,B,D,I,0, L) forms a situation structure if A is a set of 
situations, 1Z C Ax A is a binary relation such that w = w' whenever (w, s)IZ{w ' , s'), 
Z{a) C A x A for the functions Z £ {1C, B, D,T} and a £ A, and 0{a , b) C A x A 
with a,b £ A are binary relations such that s = s' whenever (w, s)Z{a){w ' , s') or 
(w, s)0{a , b)(w' , s'), and L an interpretation function that assigns a particular set of 
situations to each primitive proposition. L{p) contains all those situations in which p 
holds. 
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A speciality of CTL is that some formulae - called path formulae- are not interpreted 
relative to a particular situation. What is relevant here are full paths. The reference to 
M is omitted whenever it is understood. Note that aU f3 is true if a is true until the last 
moment before the first one in which (3 is true (alternative definitions are used in the 
literature too). 

Definition 3 (Semantics KBDIOctl)- Given a set A of agent names. A full path in 
situation structure M is a sequence y = Si, S 2 , ■ ■ ■ such that for every i > 0, Si is 
an element of A and SfiZSi+i, and if y is finite with S n its final situation, then there is 
no situation 5 n +\ in A such that 5 n lZS n +i. We say that a full path starts at S iff So = S. 
If X = So, c>i, S 2 , ■ ■ ■ is a full path in M, then we denote Si by yf (i > 0). 

Let M be a situation structure, 5 a situation, y a full path and a,b £ A two agents. 
The semantic relation \=for KBDIOctl is then defined as follows: 

51 5 \= p iff S £ L{p) and p is a primitive proposition 

52 S \= a A (3 iffS |= a and S \= (3 
5 |= ->a iff S \= a does not hold 

53 S |= Ea iff for some full path y in M starting at S, we have y \= a 
S |= Aa iff for each full path y in AI starting at S, we have y\= a 

54 S \= K a {o) iff for every S' £ A such that SIC(a)S' , S’ \= a 
S |= B a (a) iff for every S' £ A such that SB (a) S ' , S' \= a 
S |= D a {a) iff for every S' £ A such that ST>{a)S' , S' \= a 
S |= / a (a) iff for every S' £ A such that SI (a) S' , S' \= a 

5 \= O a b(a) iff for every S' £ A such that SO(a, b)S ' , S' \= a 
P X \= Xa iffy 1 \= a 

y |= aU(3 iff there is ani > 0 such that yf |= (3 and for all j (0 < j < i) , y 3 |= a 

Like Rao and Georgeff, we use standard interpretations of these operators. On j, is 
interpreted as a standard deontic operator KD [19], B as KD45, I\ as S5, and D , I as 
KD modal logic operators. The properties discussed in this paper characterize the rela- 
tion between mental attitudes of a single agent. Properties can always be expressed at 
two levels. First, we can express that all obligations of an agent towards an agent sat- 
isfy a property. In that case, the obligations are characterized by this property. Second, 
properties may hold for one particular obligation only. In that case we may say that 
this particular obligation satisfies the property, but it does not characterize the agent’s 
obligations in general. In this paper, we follow the convention that properties expressed 
using a are axioms, and thus a can be substituted by any propositional formula. 

However, it is important to notice that all properties expressed relative to a group or 
role, such as r(a) — > K a ct, can only be expressed as formulas, not as an axiom. The 
reason is, roughly, a condition like g(a) or r(a) should not be substituted by another 
proposition. For example, if r(a ) — » K a a is an axiom, then so is q — > K a a. An 
alternative way to formalize organizational structure in Rao and Georgeff’s logic is to 
index modal operators by groups and roles, and thus write the above property as an 
axiom K g ^a. The reason we made this choice of formalizing organizational structure 
in propositions is that the expressive power of the alternative representation is limited. 
The loss of relativized axioms is considered to be less severe, as the status of interaction 
axioms in this logic is problematic anyway, as discussed in Section 9. 
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4 Specification of Organizational Structure 

Organizational structure is typically specified in terms of roles and role relations. When 
agent x £ A plays the role p £ R of passenger, and has not paid before travel started, 
then he or she is obliged to pay a fine to the public transport company s. This can be 
specified by the following set of formulas, for all x, y £ A. Note that sanctions are 
modelled as obligations too, and that the violation condition is expressed using the until 
operator of CTL. 

(p(x) A (^paid^t/travelc)) — > 0 XtS fine^ 

If the public transport company s £ A has delegated the power to collect fines to the 
ticket controller, c £ R, we get (p(x) A c(y) A (^paid^t/travelc)) — > 0 XiV fine x . Such 
so-called delegation relations can become complex and are not further discussed in this 
paper. See for example, [20,21]. 

In general, obligations are created by interaction. For example, in an electronic mar- 
ket where agents are buying and selling goods, a confirmation to buy creates a obligation 
to pay for the buyer and an obligation of shipping the goods for the seller. Obligations 
may also be created by the way a social system is designed. A social system typically 
contains stable relationships between roles, which affect the obligations of the agents 
in those roles. In particular, obligations can be based on the known or believed mental 
attitudes of agents standing in a role relation. For example, the role relation cidopts£ C 
between agent a £ A and agent b £ A can be characterized by the following axiom, 
which says that agent a adopts all obligations of agent b towards some other agent 
c £ A. The following formula schema can be instantiated for all agents a,b,c £ A, 
and proposition letter q. Obviously we have an analogous property when we replace 
knowledge (K) by belief ( B ). 

(a adopts b A K a Ob, c Q ) — * O a , c q 

We can further specify obligation adoption with additional formulas. For example, the 
formula schema (r(a) A r(b)) — » a adopts b specifies that agent a adopts the obliga- 
tions of agent b when they play the same role r in the organization. In a similar way, 
K a DbOt — ■> O a ,bCn characterizes that agent a adopts the known desires of agent b as its 
obligations. Take a client-server system for example. When the server s believes that its 
client c desires a piece of information, then we can specify that the server s is obliged 
to see to it that client c gets this information. The following axiom schema character- 
izes the slave jof £ C or “your wish is my command” role relation, which says that the 
desires or intentions of master m £ A become the obligations of slave s £ A. 

(s slavejofm A K s I m q) — > 0 Stm q 

For example, reconsider the running example and assume that the passenger has not 
paid. Now we need a detection mechanism to make sure that the sanction is applied. A 
ticket controller has the institutional power to make a passenger without a ticket pay a 
fine. However, the controller does not have the power to make any passenger pay a fine. 
There must be a pretext. This can be specified as a restricted instance of the master-slave 
principle listed above. 

(p(x) A c(y) A K x Ky-< have_ticket x A K x I y fine x ) — > 0 XtV fme x 
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For violation detection, we first still have to specify that not having a ticket counts 
as evidence of not having paid. How to formalize such constitutive norms is an open 
problem in deontic logic, see for example [22-24], A very simple specification in our 
specification language is (g(x) A K x have_t icket x ) — > /^(^paid^t/traveLr), for all 
member agents x of some suitable group g £ G. 

We can further extend the logic with new group related concepts to specify require- 
ments on groups of agents. For example, the first axiom schemata for x, y £ A charac- 
terizes the property that all members of group g must know each other and they must 
be able to have the role relation ch that they can communicate with each other. This 
is called acquaintance among members of a group. Groups and roles can also be com- 
bined. For example, for any organization it is important that agents recognize the roles 
that other agents are enacting. In human society, uniforms, location (behind a desk) or 
badges are used to this purpose. A group g £ G in which a role r £ R of an agent 
a £ A is known to all agents is called transparent. 

(g(x) A g{y)) -> ( K x g(y ) A (x ch y)) ( g{a ) A g(b) A r(a) -> K b r{a)) 

Related to transparency of roles is the property of delegation transparency, which states 
that agents must know of other agents on behalf of whom they are acting. So if some 
agent a delegates a job to b, a’s role as a principal must be known. Verifying delegation 
chains is particularly important for legal applications, because the principle remains 
legally accountable. 

A promising issue in the specification of multiagent organizations is the definition 
of a set of patterns for groups, roles and role relations. Patterns have proven to be very 
useful in several areas of software engineering. For example, assume that we wish to 
define a pattern for the role relation leader £ C as the property that the agent fulfilling 
the role is able to communicate with the group members and vice versa. Also, a group 
leader must be able to delegate tasks to the group members and persuade them to have 
certain beliefs. In addition, the obligations of members of a group are the obligations 
of the group leader (a failure to satisfy an obligation by a group member is a failure to 
satisfy the obligation of the group leader), and the members should be committed to the 
task delegated to them. The following schemata characterize such a group leader. Let 
a,x £ A, g £ G, leader and com £ C be role relations that represent ‘leader of’ and 
‘able to communicate’, respectively. 
a leader x — > 

K a (a com x) A K x (x com a) A (ability to communicate) 

D a AFI x q — * AF I x q A (task delegation) 

IaB x q — > AXB x q A (persuading members) 

O x , a q — > O a , a <l A (obligation inheritance) 

I x AFq — > A(I x AFq U ( B a q V ~^B a EFq))) (committed to delegated tasks) 

An interesting question for further research is how standard patterns used in business 
modelling or software engineering can be formalized in our specification language. In 
this paper we do not consider this question, but we return to our running example. 
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5 Formalizing the Norm of the Running Example 

The public transport norm can be phrased as follows: any agent in the role of passenger 
travelling by public transport, should have paid for the trip. We choose to describe this 
norm in terms of a so called ‘deadline obligation’: “if x £ A is playing the role of 
passenger p £ R, then x is obliged towards society s to see to it that there is no history 
in which x does not pay until x travels”. 

p(x) — * 0 XtS ^E((^-pa,id x A ->travel E )t/travel a: ) 

The concept of deadline obligation is rather complex, as several alternative definitions 
can be given [25]. The concept depends on the particular interpretation of the until oper- 
ator. The formula states that the obligation applies to any agent in the role of passenger. 
However, this formula does not describe behavior. The following formula, without the 
obligation, does: 

p(x) — > -i£((-ipaid a . A ^travels) [/travel^) 

Our definition of deadline obligations is inspired by Rao and Gerogeff’s formalizations 
of commitment strategies. The main axioms discussed in temporal extensions of BDI 
logic are realism properties and commitment strategies, in particular in BDI LTL by Co- 
hen and Levesque [26] and in BDIctl by Rao and Georgeff [27, 6]. 

Realism puts a constraint on desires, with respect to what the agent believes about 
the state of the world. Some examples of realism properties are B a ot — > D a a , for 
‘overcommitted realism’ as defined in [26], D a a — > - B a ->a for ‘weak realism’ as 
defined in [27,6], and D a EFa — > B a EFa for ‘strong realism’. 

Commitment strategies are constraints on the process of intention reconsideration: 
under what circumstances is it allowed to drop an intention? Examples of commitment 
strategies are I a AFa — > A(I a AFa UB a a ) , for ‘blind commitment’, and the more 
interesting I a AFa — > A(I a AFa U{B a a V ->B a EFot)), called ‘single minded com- 
mitment’ . Whereas realism properties are static, commitment strategies are dynamic in 
the sense that they specify the temporal evolution of intentions. In the remainder of this 
section we define static and dynamic properties that involve obligations. 

Rao and Georgeff’s commitment strategies are examples of interactions of moti- 
vational attitudes and time. Such interactions also occur for desires and obligations. 
Cohen and Levesque [26] distinguish ‘achievement goals’ and ‘maintenance goals’. 
Their definition in BDIltl can be adapted to KBDIOctl as the definition of O'; b be- 
low on the left. Cohen and Levesque do not give a definition for maintenance goals, 
but they characterize the difference as follows: “Achievement goals are those the agent 
believes to be false; maintenance goals are those the agent already believes to be true”. 
This suggests that we can give a formula 0^ b a to express a maintenance obligation: 
0^f b a =def B a a A O a ,bAFa. Alternatively, we could define a maintenance obligation 
by the restriction that the goal or obligation should be maintained all the time. 

= def F a 'Ot A O a ^bAF OL O ab CX =def Fa ^ A O a ,bAG(X 

Another issue are the conditions that may discharge an obligation. Obligations typi- 
cally persist until a deadline, e.g., deliver the goods before noon, or they persist forever, 
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e.g., don’t kill. We denote a deadline obligation by O a j,(o:. d), where achievement of 
the proposition d is the deadline for the obligation to achieve a. A deadline obliga- 
tion O a b(a, d) persists until it is fulfilled or becomes obsolete because the deadline is 
reached. 



O atb (a,d) = de f A((O a ,bCx)U(aV d)) 

A deadline obligation O a ,b(o:,a), for which the only deadline is the achievement 
of the obligation itself, is called a ‘dischargeable obligation’. The definition simplifies 
to O a ,b{cx,a) =def A{(O a ,bo)Ua). Alternatively, we may characterize the property 
that obligations from agent a to agent b are dischargeable by the axiom O a ,bCt <-> 
A((O a ,bOt)Ua). Analogously we can also define dischargeable desires. For example, 
an agent may desire a receipt until it gets one. However, a drawback of the axiom is 
that it is expressed in terms of facts, which are not accessible to agents. We therefore 
replace the occurrence of a without a preceding modal operator by K a a. Moreover, 
again we believe that dischargeable obligations and dischargeable desires obey differ- 
ent discharging conditions. An obligation can only be discharged by the knowledge 
that the obliged condition is fulfilled. A desire can already be discharged by the belief 
that this is the case. Consequently, the property that obligations from agent a towards 
agent b are dischargeable, and analogously the property that desires from agent a are 
dischargeable, are characterized by the following two axioms, respectively. 

O a , b a <-> A((O a ,bu)UK a a) D a a <-*■ A((D a a)UB a a) 

We can characterize that O a f,a persists forever, i.e., that it is a ‘non-dischargeable obli- 
gation’, by O a ,bOt <-> AGOt' hO- We can also combine the definitions, such that agents 
for instance have non-dischargeable achievement obligations, or dischargeable mainte- 
nance obligations. 

As we now have specified the norm, we finally specify the four ways to realize 
that the norm is fulfilled. First we regiment the norm into the environment, such that 
agents cannot violate the norm. Then we define agents which are designed such that 
they cannot violate norms. Finally we discuss formalizations that rely on rationality 
or social control. In the formalization, we distinguish between assumptions about so- 
cieties, ticket policies, individual agents and the environment. These assumptions are 
either formalized as formulas or as axioms. The difference is roughly that axioms are 
true in any world of the model, and for axioms we can substitute the propositions by 
other propositions. The norm itself - the first formula above - can be part of those as- 
sumptions. We want to verify whether the second property follows from this. I' lns is a 
set of formulas representing assumed properties of the institution, in this case the public 
transport network, r ri , ..., I \ n are sets of formulas that represent the assumed proper- 
ties for the various roles rr, ..., r n in the institution, like passenger or ticket collector, 
r env is a set of formulas representing the assumed properties of the behavior of the 
environment, and A represents the property to be shown. As usual we use the weakest 
version of modal entailment, i.e., ip \= ip holds if and only if it is the case that when p 
is satisfied in some state of a model, than also t/> is satisfied. 
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6 Implementing a Norm in the Environment 



An important question when developing a normative system is whether the norms can 
be violated or not, i.e., whether the norms are soft or hard constraints. In the latter case, 
the norms are said to be regimented. Regimented norms correspond to preventative 
control systems in computer security [17]. For example, in the metro example it is 
not possible to travel without a ticket, because there is a preventative control system, 
whereas it is possible to travel without a ticket on the French trains, because there 
is a detective control system. Norm regimentation for agent a is characterized by the 
following axiom. 

Oa,bO ’ Oi 

The following example illustrates the specification of regimentation in the running 
example. It also illustrates that regimentation can be specified at different levels of 
abstraction. At the detailed level, it is specified precisely how the norm is implemented 
in the environment. At a more abstract level, the norm is given as an axiom, and it is 
specified that the norm is regimented - but not how it is regimented. 

Example 1 ( norm enforcement by imposing a restrictive environment). The set of agents 
is A = {x, s}, the set of roles is II = {p}, the set of groups and role relations 
is G = ch = 0, and the set of propositions is P = {travel^, have_ticket x , paid,,., 
climbed_barrier x , pass_barrier a ,}. The following formulas represent assumptions. 
(1) Having a ticket is the evidence for having paid. (2) Passengers cannot climb the 
barrier. (3) To travel, a passenger must have passed the barrier. (4) To pass the barrier, a 
passenger must have paid, or must have climbed it. 

1. /l ns = {p{x) — > AG((have_tickets — » paid x ))}, 

2. /"passenger = {AG(^climb_barrier x )}, 

3. C = {-'Zf(-'pa,ss_ba,rrier x Gtravel x ), 

4. AG(pass_barrier a . <-> (have_ticket x V climb .barrier^))} 

We now show that p(x) — > ->.E((->paid a , A -itravel^) ) U travel,. ) follows from the 
above set. Suppose no passenger is travelling; then the behavior is trivially satisfied. 
Now suppose a passenger is travelling. That means that she passed the barrier (3). That 
means she has a ticket, or else she climbed the barrier (4). This last option is ruled out 
by assumption (2). So she has a ticket, which means she paid (1). 

Instead, we can specify the system at a higher level of abstraction by specifying the 
norm and specifying that the norm is regimented. 

1- Tins = {p(x) — > O x , s -<E((-^ paklj, A -itravel x )17travel x )}, 

2- -/passenger — > Q?}, 

3. r e nv = {} 

Note that the first formula is an ordinary assumption, whereas the second formula is 
an axiom of the logic. The desired consequence p{x) — > ->/?((^paid 2 . A -4ravel x ) 
[/travels) follows directly from the assumptions. 
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7 Implementing a Norm by Designing Norm Abiding Agents 

A drawback of the regimentation property in the previous section is that it is not ex- 
pressed in terms of mental concepts, and thus agents cannot reason about it. Therefore 
we strengthen it to the case in which not only a is the case, but the agent also knows 
that this is the case. The property that the obligations of agent a towards agent b are 
regimented is characterized by the following axiom. 

Oa,b& ’ K a CX 

Note that since we have the axiom I\ a a — > a , we have that O a ,bOt — > K a a implies 
O a ,bCt — > a. This strong property can be weakened in various directions. First, we can 
weaken it in the sense that it is not necessarily a fact that the obligation is obeyed, 
but that at least the opposite is not the case, O a ,bCe — ► ~^K a ^a. Second, it can be 
weakened such that agents believe that the obligation is not violated: O a ,b& — » B a a and 
O a ,bOt — > —B a —'Ot. Third, the time of compliance to the obligation can be weakened: 
O a ,bOt — > K a AFa , or e.g., O a ,bOt — > K a AXa, etc. 

At the most abstract level, the formalization of the running example remains nearly 
the same, we replace the regimentation axiom by the epistemic variant above. Moreover, 
the logic can specify the decision making of agents at more detailed levels. In particular, 
the logic can specify when desires or obligations lead to intentions, and when intentions 
lead to actions. That is, the regimentation axiom O a , b ot — > K a a is decomposed into the 
following two axioms. 



Oa,b@- ’ Ia& 7 a G: - K a Ot 

Furthermore, there are many variants on these two axioms. For example, a variant of 
regimentation concerns conditionality with respect to a conflict between an agent’s in- 
ternal and external motivations. For example, ‘if an agent is obliged to buy a ticket, but 
desires to spend no money, then he intends to buy the ticket anyway, because he is a 
‘social’ agent that does not let his own desires overrule his obligations’. The property 
that agent a is strongly or weakly respectful with respect to agent b is characterized by 
the following two axioms. The second formula is implied by the first one if the D axiom 
->(/ a a A / a -ia) holds for modality I a . 

(O a , b a A D a ^a) — > I a a (O a , b ct A D a ^a) — > ~^I a ^a 

Finally, the intention of achieving a state can interact with obligations to satisfy the 
conditions for achieving that state. In such a case, new intentions are implied. The in- 
teraction between intention and norms and the creation of intentions can be formulated 
as the following benevolent axiom: 

I x a A 0 XtS ^E(^pUa) — > I x f3 

The specification of rational agents is one of the main issues studied in agent theory, and 
these results can be reused in KBDIOctl- However, it is also well known that modal 
logic has to be extended in several ways to make detailed agent models. For example, 
to specify agents that maximize expected utility BDIctl has to be extended in various 
ways [ 28 ]. 
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8 Implementing a Norm by Relying 
on Rationality or Social Control 

The first way in which norms can be implemented, is to rely on agent rationality and 
impose fines on norm violations. As mentioned above, the logic can specify when de- 
sires or obligations lead to intentions, and when intentions lead to actions. In particular, 
in the previous section the regimentation axiom O a ,bCt — > I\ a a is decomposed into 
O a ,bOt — > I a a and I a a — * K a a. In this section, we make sure that the agent desires to 
fulfill the obligation. That is, the regimentation axiom O a ,bCe — > K a a is decomposed 
into the following three axioms. 

Oa,b& * D a CX I a & * AT a G: 

We thus interpret the first axiom as the specification that the system is such that it is 
desired to fulfill the obligation. However, there are several ways in which the axiom can 
be interpreted. The first explanation is that the agent is norm abiding and internalizes its 
obligations in the sense that they turn into desires. For example, if an agent is obliged 
to buy a ticket, then it also desires to buy a ticket. The axiom can be weakened to 
the condition that at least the agent cannot decide to violate the obligation, e.g., at 
least it cannot desire not to buy a ticket: O a ^ot — > — I) a —-a. Instead of respectful, 
agents may also be egocentric, which can be characterized by similar properties like 
(O a ,bOt A D a ^a) — > I a ^a and ( O a ,bOt A D a ^a) — > ->I a a. 

The second interpretation of O a ,bOt — ► D a a is that the obligation turns into a desire, 
because violating the desire implies a fine. We already discussed fines in Section 4. The 
following example is a simplified version, that illustrates how the desire not to be fined 
can lead to the desire to fulfill obligations, desires. Note that in this formalization the 
derived desire may also be interpreted as a goal, which is often the case in BDIctl 
specifications. 

O ai bpaid — > A^-ipaid — > fine) (A' a (^paid — > fine) A .Define) — ■> D a paid 

The third interpretation of O a ,bOt — > D a a is that violating the obligation leads to 
social embarrassment. This can be specified analogously to fines. 

9 Related Work 

Despite the popularity of Roa and Georgeff ’s logic in agent theory to specify and ver- 
ify multiagent systems, the logical analysis of their logic is still in its infancy. Rao and 
Georgeff did not present a full axiomatization of their logic, which was only presented 
much more recently by Schild’s reduction to the /i calculus. Moreover, the axiomatiza- 
tion is restricted to the logic without any interaction axioms. In the meantime, logicians 
have restricted themselves to small fragments of their logic, for example to study the 
interaction between knowledge and time, or to study the interaction between beliefs and 
obligations. 

Within deontic logic in computer science, our work is most closely related to dy- 
namic deontic logic, extensions of dynamic logic with modalities for obligations and 
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permissions. In multiagent systems, recently norms and normative systems are dis- 
cussed, but their specification or verification has has not been addressed. In action pro- 
grams in IMPACT, there is a discussion on whether obligations can be violated, i.e., 
on norm regimentation [29]. We have addressed this issue in the context of the BOID 
project, see http://boid.info. The present paper extends our short paper [30]. 



10 Summary 

The motivation of our work is how such normative computer systems can be specified. 
This problem breaks down as follows: 

1 . How to develop a logic for specification of normative computer systems? 

2. Which kind of properties can be expressed in the specification logic? 

3. How to apply the specification logic to application domains? 

Our methodology is to specify properties involving obligations in an extension of 
Rao and Georgeff’s BDIctl [6,3-5]. Such an extension consists of an extension of 
the logic and an extension of the properties expressed in the logic. Obligations are 
motivational attitudes, just like desires, but they also have organizational aspects. This 
can be represented, for example, by introducing roles and by formalizing obligation as 
a directed modality. Thus, whereas we may say that agent a desires to prepare a report, 
we say that the agent a is obliged to prepare a report towards another agent b. We 
accomplish our extension of BDIctl with obligations in the following steps: 

- The introduction of an extension of BDIctl called KBDIOctl, that makes the dis- 
tinction between desires and obligations explicit, as well as the distinction between 
beliefs and knowledge. We extend BDIctl with directed obligations [7-11] and 
roles. 

- We introduce various single agent and multiagent properties. These properties can 
be used in a high-level design language for normative computer systems. 

- We apply the logic and the properties to the implementation of an organizational 
norm. 
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Abstract. We consider the logical representation of obligations on sta- 
tive expressions such as The yard must be clean in the context of legal 
contract formation, execution, and monitoring (cf. Wyner ([28])). In a 
contract, the expression may understood as an obligation to maintain a 
property. We use a Deontic Action Logic to represent obligations over 
the course of time (Khosla and Maibaum ([13]) and Meyer ([17])). Our 
analysis is in contrast to d’Altan, Meyer, and Wieringa ([6]), who re- 
duce deontic operators to an Alethic Logic plus a violation proposition 
(Anderson and Moore ([1])), which has no temporal component. In addi- 
tion, they use a Deontic Action Logic to represent obligations on actions. 
We claim the Alethic component of the logic is redundant for the pur- 
poses of representing obligations on stative expressions in a contract. In 
the course of the analysis, we introduce polynormativity, which contrasts 
with the binormativity of standard DAL or alethic logic plus a violation 
proposition. We discuss the advantages of polynormativity in reasoning 
from violations and fulfillments. 



1 Introduction 

We consider the logical representation of maintaining obligations on stative ex- 
pressions such as The yard must be clean , particularly in the context of legal 
contract formation, execution, and monitoring (cf. Wyner ([28]) for discussion 
of the application) . Ought-to-be statements may be understood as system invari- 
ants, those ‘normal’ properties which must be true in every state of a model. The 
problem with such system invariants is what happens when the normal property 
does not hold, in which case, a violation may arise such as may appear in sys- 
tems of fault tolerance. A deontic logic on properties is useful in defining how 
to handle violations. We also have cleontically specified actions, which we ana- 
lyze with Deontic Action Logics (Khosla and Maibaum ([13]) and Meyer ([17])). 
This paper provides an analysis of ought-to-be and ought-to-do expressions in a 
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from Hewlett-Packard. It has benefitted from discussions with Tom Maibaum, An- 
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Andrew, and HP for their support and advice. Errors rest with the author. 
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Deontic Action Logic which is suitable for legal contract modelling, execution, 
and modelling; for reasons of space, we largely largely focus on obligations, not 
permissions or prohibitions. 

The layout of the paper is as follows. In the next section, we discuss the prob- 
lem and some framework assumptions concerning agents, actions, action nega- 
tion, deontic logic ‘paradoxes’, and polynormativity. Following this, we present 
our analysis of ouglrt-to-be expressions in terms of maintaining the property 
(similar to notions discussed in Khosla and Maibaum ([13]), Sergot and Richards 
([22]), and Hilpinen ([9]). Then we compare our analysis to the presentation of 
ought-to-be expressions found in d’Altan, Meyer, and Wieringa ([6]), which pro- 
vides an overview of the issues as well as a particular analysis. Our principle ob- 
jections are that their critique of the ‘classic’ analysis of ought-to-be expressions, 
where one is forbidden to undo the property, does not eliminate the analysis. 
In addition, they introduce a logic in which ought-to-do expressions are repre- 
sented using Deontic Action Logic and ought-to-be expressions are represented 
using Aletlric logic plus a violation atomic proposition. We believe this system is 
more complex than need be and that the alethic component can be eliminated. 
Our representation also has the advantage that it defines what follows should a 
violation occur. 



2 Initial Discussion 

The following examples express obligations on actions and states respectively. 
Example 1. Bill must leave. 

Example 2. The yard must be clean. 

In (1), the agent is obligated to do a leaving action, while in (2), it would appear 
that the obligation that the yard is clean holds irrespective of an agent. Should 
either of these obligations not be met, that is, should the agent not leave or the 
yard not be clean, then the obligation is violated. Consequences may follow from 
this violation. For instance, if the agent does not leave or if the yard is not clean, 
then the agent may incur another obligation, say to pay a penalty. 

Initially, we might analyze (1) as in (3) and (2) as in (4), using the same 
deontic operator, here given as Obligated. 

Example 3. Obligated(leave(bill)), where bill is the agent of the action predi- 
cate leave , and (leave (bill)) holds or not of a state. 

Example ). Obligated (clean(the yard)), where clean(the yard) is a property 
which holds or not of a state. 

In such an analysis, the obligation operator applies equally to stative expressions 
and action expressions. The first question is whether such a uniform analysis 
is accurate; that is, whether Obligated indeed applies equally to any sort of 
expression as schematized in (5). 
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Example 5. Obligated(P), where is any sort of property of a state. 

It is clear that though the natural language deontic expressions obligated, must, 
and ought appear with both stative and action expressions, the implications from 
each case are very distinct, and in particular, with respect to how violations 
arise. For example, with respect to the ouglrt-to-do expressions, if Bill does not 
do what he is obligated to do, but performs some other action instead, then he 
is in violation. In contrast, with respect to ought-to-be expressions, a violation 
arises if the yard is not clean, irrespective of an action being performed or not. 

It would appear that having one deontic operator on both sorts of expressions 
is intuitively unacceptable and that we must instead make some sortal distinction 
between the expressions which the deontic operators apply to and also among the 
deontic operators themselves. Suppose we do sort expressions into action sorts 
and stative sorts; furthermore, we suppose two different deontic operators, one 
on actions and another on statives, which we express with ObligatedAction 
and ObligatedState 

Example 6. ObligatedAction(leave(bill)) 

Example 1. ObligatedState(clean(the yard)) 

We assume for current purposes that we can sort expressions into action and 
stative sorts 1 . The question is, then, exactly what does (6) imply in comparison 
and contrast to (7). 

Given a clear analysis of their similarities and differences, the next question 
is what is the best analysis. The space of alternative analyses (besides the one 
we dismissed above) appears to be as follows: 

1. We have a logic comprised of two distinct ‘sublogics’, where one sublogic 
defines the ought-to-be and the other which defines ought-to-do. There are no 
implicational relations between the sublogics. We do not reduce one operator 
to the other. 

2. We have a logic comprised of two distinct ‘sublogics’, where one sublogic 
defines the ought-to-be and the other which defines ought-to-do. There are 
implicational relations between the sublogics. Yet we do not reduce one op- 
erator to the other. 

3. We have a lromongeneous logic in which we define both the operators, but 
we do not reduce one operator to the other. 

4. We reduce one operator to another. 

The first position is untenable largely because of the close similarities between 
the operators; besides the similarities of form, they both imply that if something 
does not hold (or is not done), a violation is incurred. The second position is 

1 See Katz ([12]) and references therein for extensive discussion of intuitions and formal 
semantic analysis which distinguish action and stative expressions. In general, more 
research remains to be done on exactly what define action and stative expressions, 
and just which sorts the deontic operators may apply to. Such research is crucial for 
any logical analysis of actual contracts. 
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advocated by d’Altan, Meyer, and Wieringa ([6]). We argue for the third posi- 
tion. d’Altan, Meyer, and Wieringa ([6]) argue persuasively against the fourth 
position. 

In the following subsections, we touch on a range of topics relating to the 
assumptions and simplifications in which we make our proposal. Each topic is, 
in and of itself, the subject of significant research; our intention is touch just on 
those elements which relate to the core of our proposal. 

2.1 A Dynamic Logic 

We represent our contractual expressions in a Dynamic Logic rather than Stan- 
dard Deontic Logic 2 , for in a Dynamic Logic, we can represent changes in the 
values of deontically specified expressions with respect to time and the actions of 
agents. In our domain of application, which is automated contracting, we must 
account for change of states over time and as a result of actions by agents. In 
particular, we adopt a Deontic Action Logic (Khosla and Maibaum ([13]) and 
Meyer ([17])), which is based on Dynamic Logic (Harel, Kozen, and Tiuryn ([8])), 
here providing a very brief review of basic concepts. 

A Dynamic Logic is a logic of actions, where actions are state transitions given 
properties of precondition (before the performance of the action) and postcon- 
dition (after the performance of the action) states. We do not consider complex 
actions such as those formed by choice, simultaneous, negation, or sequence op- 
erators. We have a set of atomic action names {a, /?,...}, a set of agent names 

2 Standard Deontic Logic has deontic operators and action expressions. The deontic 
logic (from Kanger and Lindahl REFERENCES) is EMCP (in the Chellas classifi- 
cation). This is the smallest system containing propositional logic and the following 
axioms and rules. 

Example 8. a. O.RE: If b A B, then b OA OB 

b. O.M: 0(A AB)-» (OA A OB) 

c. O.C: (OA A OB) -> 0(A A B) 

d. O.P: -iO-L 

The difference between EMCP and Standard Deontic Logic, which is a normal modal 
logic of type KD, is that SDL is EMCP together with the necessitation rule b A, 
then bOA. However, the rule of necessitation does not play any role in the discussion 
of normative positions, so it is left out. In this system, permission P is the dual of 
obligation O: PA =def “'CHA. The Action Logic differs from Dynamic Logic in 
that it abstracts from the temporal dimension. We have agent relativized action 
operators, E a and Et, where a and b are agents, and E a A, where A is a property, is 
read as agent a sees to it that A or agent a is responsible for it being the case that 
A. Actions abide by the following axioms. 

Example 9. E.RE If A B, then E^A o E^B 

Example 10. E.T E*A —¥ A 

Note that in SDL, O (E^ F) e O (F A E s F), while in DAL, correlated expression 
[A, a] (Violation) is not equivalent to [A, a] (Violation) A Violation. 
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{A, B, . . . }, and a set of propositional letters {</>, if, . . . }. The expression [A, 
«](</>) is to be read in every state where agent A performs action a, <f> holds in 
the subsequent state. Alternatively, where we read the action as a function from 
states to states, we may say that where the agent appears and the state satis- 
fies the precondition properties specified by the ction, then the action maps the 
current state to a subsequent state which satisfies the postcondition property 
4>, perhaps along with other properties of the postcondition as specified by the 
action. 

In a Deontic Action Logic, actions are also ascribed properites such as whether 
the action is obligatory or prohibited. For example, where obligation, permission, 
and prohibition are represented by predicates of actions Obligated, Permitted, 
and Prohibited, we have expressions of the form Obligated(A, a), Permit- 
ted^, a), and Prohibited(A, a). We assume agents in every case and discuss 
this further below. In Khosla and Maibaum ([13]) and Meyer ([17]), a designated 
property Violation, read as violation, is introduced (see Anderson and Moore 
([1]) for a precursor in Alethic Modal Logic); a state in which this property 
holds is understood to be in violation or to be flagged for violation, which is to 
say it is non- normative. Such an analysis characterizes a binormative analysis, 
for states are either normative or non-normative. For the moment, it is easier 
to discuss the notion of prohibition rather than our target notion of obligation. 
The meaning of Prohibited(A, a) is then given in terms of Dynamic Logic and 
a violation flag. 

Example 11. Prohibited(A, a) = [A, a] (Violation) 

In other words, if A does a, then in the subsequent state, a violation is marked. 
One way to understand Prohibited is as an operator on actions - a function 
from actions to actions such that where the preconditions of the action are met 
and the action is performed, the postcondition state bears not only the properties 
ascribed by the action, but in addition, a designated violation property, which 
is used to signal that what was forbidden has occurred. 

Obligation with respect to an action is somewhat more complex. We shall 
make a simplying assumption for the purposes of this presentation (see Meyer 
([17]), Khosla and Maibaum ([13]), and Broersen ([2]) for discussion action nega- 
tion, particularly Broersen which is similar to our view). For obligations on ac- 
tions, a violation arises where some action other than the obligated action is 
performed; where a is the action, we may indicate an alternative to a with a, 
which may be understood as an element of the set of actions without a: a £ {a, 
/3, . . - a, where the set of actions is finite. 

Example 12. Obligated(A, a) = [A, a] (Violation) 

Given that actions can result in violations, the performance of a prohibited 
action or failure to perform an obligatory action is marked rather than ruled 
out by the system. In particular domains, such as fault tolerance or contract 
performance, we want to represent and reason with respect to what is prohibited 
or obligated; we cannot simply rule out such behavior, for the fact is that it does 
occur. Particularly in the domain of contract modelling and analysis, a Deontic 
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Action Logic is key, for with it we can represent and reason about the behaviors 
of the agents as they perform error prone, by accident or design, actions over the 
temporal course of the contract. As the agents perform the actions, they change 
states; we are interested in the deontic specification of such state changes. 

In addition to these conceptual advantages, as Meyer ([17]) points out, a 
Deontic Action Logic avoids many of the so-called paradoxes which arise with 
Standard Deontic Logic, for many of the paradoxes either are not well- formed, 
have solutions (cf. discussion of free choice permission in Meyer, Weigand, and 
Wieringa ([18])), or are not worse than those suffered by other formalizations 
of deontic logic. In any case, the paradoxes do not create inconsistency, but 
are cases of overgeneration in which some of the formulas do not correlate well 
with our intuitive interpretation of what the expression should mean. There 
are a variety of ways to see to it that the logic does not overgenerate while 
preserving the appropriate expressions. Given that we only consider well-formed 
and acceptable formulas, the problem of the paradoxes does not bear on our 
discussion. We also have little to add to the discussion of Normative Positions 
(Sergot ([24]), Sergot ([23]), Sergot and Richards ([22]), and Jones and Sergot 
[11]), the aim of which is maximally consistent sets of expressions of actions and 
deontically specified actions in a state. 



2.2 The Role of Agents 

As made clear in the literature on the ouglrt-to-be and ouglrt-to-do distinction 
(cf. d’Altan, Meyer, and Wieringa ([6]), Forrester ([7]), Horty ([10]), Broersen 
and van der Torre ([3]), and references therein), a key element of the discus- 
sion is the presence or absence of an agent in the logical analysis as well as the 
distinction between personal and impersonal obligations (cf. Kroglr and Her- 
restad ([14]). For instance, D’Altan, Meyer, and Wieringa ([6, :1]) claim that 
ought-to-be statements “. . . express a desired state of affairs without necessarily 
mentioning actors and actions....”. Furthermore, D’Altan, Meyer, and Wieringa 
([6, :78]) follow Castaneda (1970:452) “...in separating deontic statements into 
those that involve agents and actions and support imperatives (ouglrt-to-do) 
and those that involve states of affairs and are agentless and have by themselves 
nothing to do with imperatives.” We should point out that there is a difference 
between the absence of an actor in the linguistic form of an expression such as 
Jill was pushed and the absence of that actor in the semantic representation. 
However, to discuss this further would require a digression into the syntax and 
formal semantics of natural language such as found in Wyner ([26]) and is outside 
the scope of this paper. 

For our purpose, which is to provide analyses of contractual terms, we may 
make a simplifying assumption, namely, that every deontically specified expres- 
sion has an agent which bears the obligation with respect to the action or prop- 
erty; this agent may be explicitly given or implicit (cf. Wyner ([28]) for further 
discussion). The reason for this assumption is straightforward: in the cases under 
study, contracts are explicit agreements in which the parties agree to be bound 
by the terms of the contract. The parties are bearers of the obligations, which we 
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designate as the agents of actions and holders of properties. On the one hand, 
this may limit the applicability of the proposed analysis; on the other hand, 
it places a criteria which other analyses must satisfy in order to be of use in 
representing contracts, for ouglrt-to-be expressions must include some agentive 
bearer of the obligation. 

2.3 Refinement of the Violation Atom — Polynormativity 

In the Deontic Action Logics of Khosla and Maibaum ([13]) and Meyer ([17]), 
deontically specified actions can lead to a subsequent state in which an atomic 
violation property holds or not. The purpose of introducing the violation prop- 
erty is to allow one to reason with violations rather than simply ruling them out. 
However, as argued in Wyner ([27]), it is not enough to have but one atomic 
violation property for reasoning about violations in contracts, for simply put, 
any two violations are, then the same. For example, if an agent Jill violates 
an obligation on her behavior and another agent Bill violates an obligation on 
his behavior, the violation is the same. However, the consequences of agent’s 
action may differ; that is, Jill’s violation may result in one penalty, while Bill’s 
violation results in another penalty. We want the violation markers to be such 
as to differentiate among the agents and actions. This is particularly important 
in a legal setting where it is crucial to apply sanctions to particular individuals 
for particular actions. The theories of Khosla and Maibaum ([13]) and Meyer 
([17]) do not sufficiently discriminate in this way, which is characteristic of bi- 
normataive theories, that is, theories which only distinguish between normative 
and non-normative states. 

Our approach provides fine-grained distinctions among violations (or fulfill- 
ments) so as to support reasoning from them. We can call it a polynormative 
theory (cf. Wyner ([27])). Somewhat similar proposals appear in d’Altan, Meyer, 
and Wieringa ([6, :108-109]) and van cler Meyden ([16]), though of more limited 
use. Let us first consider the general form and then a particular example. In (14), 
we abstract from the form of (13), where P is some predicate on agent-action 
pairs, and Q is some proposition which follows from performance of the action 
‘under’ P. 

Example 13. Prohibited(A, a) = [A, a] (Violation) 

Example lfi P(A, a) = [A, a](Q) 

The predicate P is then defined in the logic in terms of how it alters the perfor- 
mance of the action a by that agent A, in this case by stipulating that after A 
does a Q holds, which need not have been the case where P not to predicate of 
the agent and action. In effect, P ascribes a value to A’s performance of a, and 
we may call any dynamic logic which supports this schema a Value Action Logic. 
The Deontic Action Logics of Khosla and Maibaum ([13]) and Meyer ([17]) are, 
then, instances of a Value Action Logic, where P is the predicate Prohibited and 
Q the proposition Violation. Different logics are defined by how the values on 
actions change what holds after the performance of the action. Note that from 
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the schema in (14), we cannot judge whether A’s performance of a is or is not 
ideal or of some lesser status; this is a judgement lain over the expressions, not 
intrinsic to the logic itself, and not clearly relevant to them (cf. comments by 
Meyer ([17, : 126] ) on ideality in deontic logic). 

Instead of (13) as an instance of (14), we may have (15), where S and T are 
predicates of agent-action pairs. 

Example 15. S(A, a) = [A, a](T(A, a)) 

We suppose that S(A, a) is defined in terms of an action, while T(A, a) is a 
proposition which is not defined in terms of an action, but is a proposition which 
holds of a state. We can redefine Prohibition in these terms. ProlribitedAction(A, 
a) says that A’s performance of a is prohibited, which means that were A to 
perform a , it would lead to a state marked with ViolationProhibitionAction(A, 
a), which indicates what was prohibited has been performed. 

Example 16. ProlribitedAction(A, a) 

= [A, a](ViolationProhibitionAction(A, a)) 

What follows from ViolationProhibitionAction(A, a) may be further specified, 
for example, what further properties or actions are implied. To structure viola- 
tions, we can define implicational relationships among them, or for that matter 
introduce fine-grained markers for reward (cf. Meyer ([17, :125])). 

To get a flavor of the utility of this format, consider an example. Suppose 
Bill is obliged to leave the office at 5pm, Bill is prohibited from buying alcohol 
after 11pm, and Bill is prohibited from driving over 60 MPH. Jill is only prohib- 
ited from buying alcohol after 11pm. In a system with but one atomic violation 
marker, any violation would result in Bill’s current account being debited £100. 
This seems unreasonable, and we would like to associate the violation with par- 
ticular agents and actions. For instance, Bill’s violation of leaving the office at 
the wrong time leads to a debit of £10, his violation of buying alcohol too late 
costs him £20, and his violation of driving too fast costs him £50. Finally, Jill’s 
violation leads to a debit of Jill’s account of £20. Thus, Jill’s violation leads to 
a violation particular to Jill, and a consequent sanction; Bill’s violations only 
lead to sanctions on Bill, and these may be cumulative, which could not be so 
with but one atomic violation property. 

We can express the cleontically specified actions as follows, where we assume 
actions such as leaveOfficeAt.5pm are defined in the logic. 

Example 17. Obligated Action (Bill, leaveOfficeAt5pm) 

= [Bill, leaveO f ficeAtbpm] 

(ViolationObligationAction(Bill, leaveOfficeAt5pm)) 

Example 18. ProhibitedAction(Bill, buyAlcolrolAfterllpm) 

= [Bill, buyAlcolrolAfterllpm] 

(ViolationProhibitionAction(Bill, buyAlcolrolAfterllpm)) 

Example 19. ProhibitedAction(Bill, driveOver60mph) 

= [Bill, driveOver60mplr] 

(ViolationProhibitionAction(Bill, driveOver60mplr)) 
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Example 20. ProhibitedAction(Jill, buyAlcoholAfterllpm) 

= [Jill, buyAlcoholAfterllpm] 

(ViolationProhibitionAction(Jill, buyAlcoholAfterllpm)) 



Furthermore, we may define the system such that from violations with respect 
to deontic specifications, agents, and actions, specific consequences follow, here 
just that additional obligations are incurred. 

Example 21. ViolationObligationAction(Bill, leaveOfficeAt5pm) 
ObligatedAction(Bill, pay£10) 

Example 22. ViolationProlribitionAction(Bill, buyAlcoholAfterllpm) 

— > ObligatedAction(Bill, pay£20) 



Example 23. ViolationProhibitionAction(Bill, driveOver60MPH) 

— > ObligateclAction(Bill, pay £50) 

Example 24- ViolationProhibitionAction(Jill, buyAlcoholAfterllpm) 
— > ObligatedAction(Bill, pay-£20) 



By the same token, later we introduce markers for reward or fulfillment of 
an obligation (Meyer ([17]) has a somewhat similar basic notion.) Our system is 
richer and more flexible in that the deontic operators and their correlated vio- 
lations or fulfillments can be related to a range of parameters and implications. 



3 Ought-to-Be Operators Expressed 
in a Deontic Action Logic 

We want a representation of the obligation The yard must be clean such as 
might appear in the context of a legal contract. By assumption, one of the 
contractual participants is the agent of this obligation; this in turn implies that 
when the state fails to hold, the agent is liable to suffer sanction. Consider that 
the expression appears in a rental contract as part of the reponsibilities of a 
tenant. Intuitively, it means that the tenant has the obligation to keep the yard 
clean over the period of time of the tenancy. Of course, at the beginning of the 
tenancy, the yard may not be clean, in which case, the tenant is obligated to clean 
it; not cleaning the year implies a violation. Alternatively, the yard may start 
out clean, but become dirty, in which case, the tenant is obligated to clean it, or 
again suffer a violation. We call this interpretation of an ouglrt-to-be expression 
an obligation to maintain a state , for the agent is obligated to maintain a state 
or suffer violations. The tenant’s satisfaction of the obligation over the course of 
the tenancy may be specified by the contract, for example that the yard is clean 
for a certain length of time, that the yard is not dirty when it is inspected, or 
that only a certain number of violations arise. This allows a flexible notion of 
satisfaction of the obligation, for it allows some violations to occur; however, we 
do not have space here to discuss this topic. 

Our formal expression of an obligation to maintain a state is as follows. We 
assume deontic predicates ObligatedState, PermittedState, and ProhibitedState, 
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which are of type <Agt, Formula>, where Agt is an individual with the agentive 
properpty and Formula is a formula of first-order predicate logic. Our definition 
of an obligation to maintain a property with respect to an agent Agt and a for- 
mula <f> is defined in a Deontic Action Logic. Just as we have markers to indicate 
violation of an obligated action, we may indicate fulfillment with FulfilledObli- 
gatedState(A, <f>). There are constants and variables of agents and actions: Agt 
is a constant and Agt x is a variable of type agent. We may suppose that </> is 
The yard is clean ; Agt denotes some particular individual. 

Definition 1. ObligatedState(Agt, <j>) = 

[4> —> [FulfilledObligatedState(Agt, <f>) 

A 3 Agt x 3a [ProhibitedAction(Agt x , a) 

A [Agt x , ct](—i(f> A Violation-ObligatedStatefAgt, < j>)) 

A 3/3 [[Agt, (3](<f>) A ObligatedAction(Agt, [3)]]]] A 
[-> <f> -A [Violated- ObligatedState( Agt, <j>) 

A 3y [[Agt, ' y]((f> ) A ObligatedAction(Agt, j)]]] 

There are two main portions on the right hand side of the definition. The first 
portion begins where <j) is the antecedent of the first conditional; the second 
portion begins with the case where ~i(f> is the antecedent of the second conditional. 

Suppose (f> holds. This implies that the obligation is marked as being fulfilled. 
In addition, we assume that for some agent and some action, it is forbidden 
for that agent to do that action. The action is one which undoes the property 
and introduces a violation marker. In addition, an obligation is introductecl to 
produce a subsequent state in which the property holds. We return in a moment 
to the import of the indefinite agent and this additional obligation. 

Suppose -i <j>. Therefore, the obligation is marked as being in violation, and 
an obligation is incurred on the original agent to do some action which results in 
the property holding again. For legal contracting, this seems to be a reasonable 
condition, for it may be the case that an agent in a contract accepts an obligation 
with respect to a state which ought to hold but does not hold at the time the 
obligation is incurred. The agent starts off on the wrong foot in that the agent 
already is marked for having violated the obligation. The significance of this is 
discussed later. There is a degree of redundancy between the consequents of the 
first and second portions, but it is worth it to deal with such initial states where 
the obligated property does not hold. 

This formulation of an obligation to maintain a state implies that there are 
no obligations with respect properties where an agent cannot undo the property. 
Suppose we were to have an expression in a contract such as ObligatedState(A, 
P V -iP). Since it is always true in every state that P V ~^P, then the agent has 
fulfilled the obligation. But in addition, there must be some agent who performs 
some action such that were the agent to perform the action, P V ->P is false. 
Since there cannot be any such action, the consequent of this portion is false, 
making the whole expression false. For the representation of contracts, this seems 
reasonable: no contract will include some obligation with respect to a property 
which has a truth value which cannot be altered in the model. 
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Consider a weaker case, whether an agent can bear an obligation that the 
yard is clean, but not have the capacity to perform an action to either undo 
the property or to redo it as needed (cf. d’Altan, Meyer, and Wieringa ([6, 
:80])). The analysis suggests that such an agent can bear such an obligation, 
depending on what it means for the agent to have the capacity. If the property 
is true, then the agent fulfills the obligation; were some other agent to undo 
the property, then the agent would be in violation. Where the property is false, 
then the agent is again in violation. Where the agent is in violation, the agent 
is obligated to do something to bring about the property holding. What actions 
may count towards fulfillment of this latter obligation depend on circumstances; 
for example, the agent bearing the obligation may perform an action which 
designates someone else to perform the action. If it is the case that the agent 
has no capacity whatsoever, say the agent is comatose, then it seems reasonable 
to say that the obligation no longer holds. 

We believe these claims are reasonable for contracts (cf. Wyner ([28])). Sus- 
pensions or reinterpretations of contractual obligations are common in those 
portions of a contract having to do with exceptions such as should the country 
be at war, or where there is a natural disaster, or where the agents are somehow 
incapacitated with respect to performance requirements. In such cases, contrac- 
tual obligations can be suspended because the agents cannot perform the actions 
needed to satisfy them. Along these lines, we may distinguish ways in which 
the agent is incapacitated and subsequently vary the violations. One distinc- 
tion might be between a natural disempowerment, a self-induced disempower- 
ment, and disempowerment induced by another. Whether or not the obligation 
is maintained as well as what penalties follow may vary. For example, in case 
of a horrendous natural disaster, one’s debt obligations may be ‘forgiven’ and 
no violations follow. But, should one induce one’s own poverty such that debt 
obligations cannot be met, then one might bear a violation which introduces 
subsequent obligations; Chapter 11 Bankruptcy law in the United States does 
not obviate the obligations and violations, but marks the violation and replaces 
the original debt obligation with other obligations. Finally, if one is robbed so 
cannot meet one’s debts, one might still have the same obligations as before; the 
insurance industry is built around the notion of protecting oneself from natural 
disaster or disaster caused by others so as to meet one’s obligations. The anal- 
ysis we have presented so far could express such differences by marking agents 
and actions with respect to their properties and associating them with different 
violations. 

We should return to consider the indefinite agent and action of the first 
portion. We could, if we wanted, be more specific, say for a specific obligated 
property, we can define which agent and which action must be here. It is an 
advantage to leave the definition underspecified on this point. Moreover, it ex- 
presses an interesting notion as it is. Suppose Bill is the one who is obliged 
with respect to the property of the yard being clean. It implies that he should 
not do anything to make the yard unclean. Furthermore, should any agent do 
something to make the yard unclean, then Bill bears the violation. Say the wind 
blows leaves into the yard, Bill is in some sense still responsible with respect 




Maintaining Obligations on Stative Expressions in a Deontic Action Logic 269 



to the obligation to keep the yard clean. True, Bill did not do anything wrong 
himself, but he does bear responsibility, which means here that he bears the con- 
sequences of the property not holding. That he bears responsibilty in this way 
might motivate him to do what he can to prevent other agents from inducing 
the violation, say by cutting down all the trees in a 10 mile radius. 

Both portions (one where <f> holds and the second where —><p holds) introduce 
obligations to perform an action which returns a state in which the property 
holds. For the first portion, this obligation is incurred only where the property 
has become undone. In some cases, it is not possible to perform an action such 
that 4> holds again. For instance, suppose one is obligated to maintain some real 
estate forever wild; once this has been violated, say by constructing a highway 
through it, no action can return it to it formerly pristine wild state. Instead, 
a compensatory obligation may be incurred. For example, we might say the 
following for some specific properties ip and 7r, where ip is A piece of real estate 
is wild and 7 r is pay compensation. We see in the following that where the initial 
property is violated, some compensatory action is obligated. Of course, where ip 
= 7 r, Definition (2) is equivalent to Definition (1). 

Definition 2 . ObligatedState(Agt, ip) = 

[ip —> [Fulfilled- ObligatedState(Agt, ip) 

A 3Agt x 3a [ProhibitedAction(Agt x , a) 

A [Agt x , a](~>ip A Violation-ObligatedState(Agt, (p)) 

A 3/3 [[Agt, (3](ir) A ObligatedAction(Agt, [3)]]]] A 
[~iip — > [Violated- ObligatedState( Agt, ip) 

A [[Agt, 7 ](n) A ObligatedAction(Agt, j)]]] 

Finally, notice that the definition of ObligatedState(Agt, <p) introduces four 
different ways in which violations may arise, each of which may have distinct or 
interrelated consequences. There is the case where the property does not hold in 
the state in which the obligation is given, which results in a direct violation of 
the obligation. Related to this case, there is the potential violation which follows 
from failing to perform the obligated action to bring the property about. There 
is the case where the property does hold in the given scenario, but in which 
an agent performs some action which undoes it; this induces a violation on the 
obligation as well. And finally, in this subordinate state, there is the obligation 
to perform an action which results in a scenario in which the property again 
holds; the failure to perform this action could result in a violation as well. These 
violations allow us great flexibility in defining what sorts of consequences flow 
from the violations. Perhaps, for example, while it is best if the agent never 
undoes the property, should the agent undo it, it is not punished, so long as the 
agent does something to bring the property to hold again. In such an instance, it 
is only in the case where the agent both undoes the property and does nothing 
to bring the property to hold again which meets the sanction. Or, alternatively, 
it could be the case that undoing the property meets some sanction, and failing 
to redo it is marked but not sanctioned. Or, that undoing the property meets 
some sanction and failing to redo it meets a further and worse sanction. 
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4 d’Altan, Meyer, and Wieringa ([6]) 

In this section, we discuss the analysis of ought-to-be and ought-to-do opera- 
tors of d’Altan, Meyer, and Wieringa ([6]). They argue that cleontic operators 
on properties cannot be defined as expressions in a Deontic Action Logic, but 
instead provide a mixed modal-dynamic system, which includes both the stan- 
dard modal operators such as necessity □ and possibility O, as well as the action 
operators. The deontic operators on properties are defined with modal operators 
and the violation property, following Anderson and Moore ([1]). The deontic 
operators on actions are defined along the lines of Meyer ([17]) which is similar 
to Khosla and Maibaum ([13]). We claim that the alethic component is not nec- 
essary, but as we have shown, a Deontic Action Logic is enough to can capture 
the essential interpretation of deontic operators on properties. In the following 
section, we discuss some of the formal aspects of their analysis, starting with 
their discussion of different ways to reduce ouglrt-to-be to ouglrt-to-do, followed 
by a presentation of their analysis, and finish with some discussion. 

4.1 Discussion of Potential Reductions 

d’Altan, Meyer, and Wieringa ([6]) discuss four different attempts to reduce 
ought-to-be statements to ought-to-do. The formalizations are given in terms of 
state and action deontic operators, which we have indicated with ObligatedState 
and Obligated Action. We have propositions (j> and action expressions [a\(f> as 
before. Expressions such as ObligatedAction(a) are also understood as before 
except that d’Altan, Meyer, and Wieringa ([6]) do not include the agent in the 
representation. The target is the interpretation of ObligatedState (a). 

The various proposed reductions are as follows, where the reduction is first 
given informally and then formally. In each, the attempt is to reduce the obli- 
gation on a state to some expression in a Deontic Action Logic. 

First Reduction 

— A property <j) of a state-of-affairs is obligatory iff the property is a result of 
an obligatory action. 

— ObligatedState (0) =def there is an action a such that [a]<f> A Obligated- 
Action(a) 

Second Reduction 

— A property (f> of a state-of-affairs is obligatory iff all actions that lead to the 
state of affairs (/) are obligatory. 

— ObligatedState (ft) =def for all actions a, [a](j) —> ObligatedAction(a) 

Third Reduction 

— A property <j> of a state-of-affairs is obligatory iff it is prohibited from undoing 
it. 

— ObligatedState ((/>) =def for all actions a, [a]-xf) —> ProhibitedAction(a) 
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Fourth Reduction 

— A property (f> oi a, state-of-affairs is obligatory iff all actions which result in 
<f> are obligatory as well. 

— ObligatedState((/>) =def for all actions a, a <j) —> ObligatedAction(a), 
where a <f> means doing a results in <j) and not doing a results in -i<t> 

d’Altan, Meyer, and Wieringa ([6]) argue that each of these attempted reductions 
fail, and so motivate their analysis of ObligatedState(</>) in an Aletlric Logic with 
a violation atom. 

We see common themes in the first, second, and fourth reductions, namely 
that the obligatoriness of the property holds with respect to obligatory actions 
which result in states where the property holds. For example, following the first 
reduction, if it is obligatory to clean the house, which results in the house be- 
ing clean, then it is obligatory for the house to be clean. These definitions arise 
from an attempt to define obligated-to-be entirely in terms of obligated-to-do, 
rather than, for example, defining obligated-to-be in terms of deontically speci- 
fied actions along with additional properties. The only definition which breaks 
this pattern is the third reduction, which defines obligated-to-be in terms of 
prohibition on an action. d’Altan, Meyer, and Wieringa ([6]) have a range of 
objections against each of these proposals; we largely agree with the thrust of 
their comments about the first, second, and fourth. However, we do not agree 
with them concerning the third proposal, and accept the principle intuition it 
represents, so we discuss it further. 



Discussion of the Third Reduction. The third analysis expresses a negative 
relation between the obligatory property and actions. This is the classical view 
that a property is obligatory if it is prohibited from undoing. They report no 
counterexample in the left to right direction of the definition, and we agree. On 
the other hand, in the right to left direction, the problem is that if there are no 
actions which lead to —>(f>, then the conditional holds, and therefore the property 
is obligatory. This seems unreasonable, so they dismiss this analysis. 

However, we do not accept their view of this case. Consider again our simple 
example, where it is obligatory that the yard be clean. In the case where the 
yard is clean, the obligation is satisfied, and in addition, one is prohibited from 
doing an action which would induce a state in which the yard is not clean. 
Alternatively, if the yard is not clean from the moment the obligation is incurred, 
then a violation is introduced (this is our case of starting on the wrong foot); it is 
not relevant whether the performance of some action has resulted in the property 
not holding. While it may seem unduly harsh to introduce a violation from this 
point, it need not be, for the implications of the violation depend on defining the 
consequences, which have not yet been given. For instance, it is possible to define 
such a violation in such a circumstance so it has no significant consequences. 
This is where a polynormative analysis is better than a binormative analysis, for 
violations can be fine-grained and support subtle implications. However, d’Altan, 
Meyer, and Wieringa ([6]) do not consider this interpretation, reject the third 
reduction, and propose a combined modal-deontic analysis. 
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4.2 A Sketch and Discussion of the Formal Analysis 

Having rejected all potential previous proposals in which ought-to-be is defined 
in terms of ouglrt-to-do, D’Altan, Meyer, and Wieringa ([6]) make a combined 
proposal, which we sketch here. They assume the reduction in Anderson and 
Moore ([1]) of deontic operators on properties to alethic modal logic plus a des- 
ignated violation proposition; this is alethic modal logic of type S5, with the 
modality □, read as necessarily , and a designated Violation atomic proposi- 
tion. D’Altan, Meyer, and Wieringa ([6]) assume the Deontic Action Logic of 
Meyer ([17]). In the following, we give just the axioms for ObligatedState(^) 
and Da. They call this system Propositional Deontic Logic with the Anderson 
and Meyer’s reductions. 

Axiom 1 (ObligatedState). ObligatedState ((/>) tA D(—i<j> — > Violation) 
Axiom 2 (Da). D<f> — > [a](f> 

Notice that should ObligatedState^) hold, Violation) holds by 

definition. By axiom Da, this implies that [a](-> <f> — > Violation); that is, we have 
the following theorem: 

Theorem 3. ObligatedState ((f) ) —> [a](~«j) —> Violation). 

This says that if <f> is obligatory, then any action a, were it performed, results 
in a state such that if then Violation holds. So, if the action results in -i<f>, 
Violation also holds. It must be the case that the expression [a](->^> —> Violation) 
is vacuously true in the initial state. This theorem corresponds to the first portion 
of our analysis and prohibitions to undo properties. The axiom ObligatedState 
implies that should the property (f> not hold in the initial state, then there is a 
violation, which corresponds to the second portion of our analysis. 

We see, then, that this analysis yields a similar logic, but requires the intro- 
duction of the alethic component with the violation proposition. In our analysis, 
this is not necessary. 

Two further objections can be raised, the first relatively minor, but the other 
a more conceptual issue. As discussed earlier, d’Altan, Meyer, and Wieringa ([6]) 
suppose that obligated-to-be expressions need not be specified with respect to 
an agent, while actions must have agents. We can have the following expression, 

Example 25. ObligatedState(</>) — > [A, a] (-></> — > Violation). 

However, it is hard to see is is useful in contracting, for it essentially says that an 
obligation on a state implies that for every agent and every action, should they 
perform the action which results in a state with —>(j) then induces the violation. 
For our purposes, one agent may have the obligation to maintain a state, while 
another not, and it ought to be the case that only actions of the bearer of 
the obligation are relevant. We want to explicitly relate a particular agent’s 
obligations, whether to properties or to actions, and the sanctions the agent 
suffers. 

The second is more important. While d’Altan, Meyer, and Wieringa ([6, 
:112]) have a system which has both property and action deontic operators in 
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an integrated system, they point out that “...no specific relations between them 
are assumed other than those that follow immediately from both reductions to 
alethic modal logic.” In other words, the operators are not intrinsically logically 
related (d’Altan, Meyer, and Wieringa [6, :112]): “In this sense, the relation 
between ouglrt-to-be and ouglrt-to-do remains rather extensional.” This, we be- 
lieve, is a deep conceptual flaw. In other words, according to them, it is but 
‘incidental’ or ‘arbitrary’ that the two notions are so similar in form, interpre- 
tation, and use of violations. Others might use just such similarity to argue for 
some underlying relation between them, preferably deriving one from the other, 
or at least expressing them both in terms of similar basic notions, as we have. 
Our analysis accounts for the similarity of the operators better than d’Altan, 
Meyer, and Wieringa ([6]) without needing to introduce the alethic component. 

5 Conclusion 

We have provided an analysis of stative obligations expressed in a Deontic Action 
Logic. We have a simpler and more uniform way to express any sort of deontic 
expression, whether an action or a property. We have shown that this analysis can 
represent detailed and intuitively plausible logical representations, particularly 
as the obligation is maintained over time. Some topics which could not be covered 
here relate to the fulfillment and end of an obligation on a property as well 
as the relation of obligations on properties to permissions and prohibitions on 
properties. 
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